Database/AI/ML frameworks & serving
TorchServe (model/workflow API): Information disclosure of files on the serving host
CVSS 5.3CVE-2023-48299AI/ML frameworks & servingcurated
Impact
Information disclosure of files on the serving host
Who can reach it
Network to the management API
What to do
Patch to 0.9.0+; firewall the management plane
References
Related entries
- llama.cpp (RPC backend): Arbitrary address read via `rpc_tensor.data`CVE-2024-42478 · llama.cpp (RPC backend)Medium
- HuggingFace transformers: ReDoS in `convert_tf_weight_name_to_pt_weight_name`CVE-2025-5197 · HuggingFace transformersMedium
- mcp-kubernetes-server: chained kubectl commands bypass the read-only --disable-write/--disable-delete guardsCVE-2025-59376 · feiskyer mcp-kubernetes-server (--disable-write / --disable-delete command guards)Medium
- Hugging Face Transformers: ReDoS in the English number normalizer burns CPU on crafted inputCVE-2025-6051 · Hugging Face Transformers (EnglishNormalizer.normalize_numbers)Medium
- BentoML OpenLLM 0.6.30 (async_run_command in src/openllm/common.py): A model repository directory name flows unescapedCVE-2026-15035 · BentoML OpenLLM 0.6.30 (async_run_command in src/openllm/common.py)Medium
- JupyterHub: unauthenticated logins write unbounded usernames to the log, exhausting storageCVE-2026-54338 · JupyterHub form-based login authenticators (failed-login logging)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.