Database/AI/ML frameworks & serving
vLLM (MessageQueue / ZMQ): `pickle.loads` on socket data
CVSS 9.8CVE-2024-11041AI/ML frameworks & servingcurated
Impact
pickle.loads on socket data → unauthenticated RCE
Who can reach it
Unauthenticated network to the vLLM internal ZMQ socket, reachable by a co-tenant
What to do
Upgrade; bind ZMQ to loopback and enforce per-tenant network policy. Internal IPC sockets must never cross the tenant boundary
References
Related entries
- Qdrant (snapshot upload): Path traversal + arbitrary file upload via `/collections/{c}/snapshots/upload`CVE-2024-2221 · Qdrant (snapshot upload)Critical
- ClearML fileserver: No authentication — arbitrary read/write/delete of all stored artifactsCVE-2024-24592 · ClearML fileserverCritical
- langchain-experimental: Second bypass of CVE-2023-44467CVE-2024-27444 · langchain-experimentalCritical
- Pure Storage FlashArray Purity API endpoint: A specific call to a FlashArray endpoint escalates the caller's privilegesCVE-2024-3057 · Pure Storage FlashArray Purity API endpointCritical
- TorchServe: `allowed_urls` bypassCVE-2024-35198 · TorchServeCritical
- Keras / TensorFlow: Arbitrary code injection in Keras < 2.13 via Lambda-layer model loadingCVE-2024-3660 · Keras / TensorFlowCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.