Database/AI/ML frameworks & serving
Ray (`/log_proxy`): SSRF from the dashboard
CVSS 9.1CVE-2023-48023AI/ML frameworks & servingcurated
Impact
SSRF from the dashboard
Who can reach it
Unauthenticated network to the dashboard
What to do
No vendor patch (same disputed position); isolate
References
Related entries
- Qdrant (snapshot recovery): Arbitrary file read and write during snapshot recoveryCVE-2024-3829 · Qdrant (snapshot recovery)Critical
- ONNX (`download_model`): Arbitrary file overwriteCVE-2024-7776 · ONNX (`download_model`)Critical
- MLflow (pyfunc tar extraction): Arbitrary file write from crafted tar entriesCVE-2025-15031 · MLflow (pyfunc tar extraction)Critical
- NVIDIA Triton (HTTP server): Attacker can start a reverse shell from the HTTP serverCVE-2025-23317 · NVIDIA Triton (HTTP server)Critical
- SGLang (expert-parallel backup ZMQ PULL): Unauthenticated, unvalidated deserialization on a routable interfaceCVE-2026-14890 · SGLang (expert-parallel backup ZMQ PULL)Critical
- LiteLLM (JWT auth): Auth bypass when `enable_jwt_auth` is setCVE-2026-35030 · LiteLLM (JWT auth)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.