Database/AI/ML frameworks & serving
Jupyter Server Proxy: Authentication weakness in proxied-process access
CVSS 9.0CVE-2024-28179AI/ML frameworks & servingcurated
Impact
Authentication weakness in proxied-process access
Who can reach it
Network user of a JupyterHub deployment
What to do
Upgrade; commonly deployed on managed GPU notebook platforms
References
Related entries
- Jupyter Server Proxy: Unauthenticated web access to a user's proxied processesCVE-2024-35225 · Jupyter Server ProxyCritical
- vLLM (Mooncake): Unsafe deserialization over ZMQ/TCP bound to all interfacesCVE-2025-29783 · vLLM (Mooncake)Critical
- Keras (`utils.get_file`, tar extract): Path traversal on tar extractionCVE-2025-12060 · Keras (`utils.get_file`, tar extract)High
- llama.cpp (`gguf_init_from_file_impl`): Integer overflow in GGUF initCVE-2025-53630 · llama.cpp (`gguf_init_from_file_impl`)High
- Pure Storage FlashArray VASA provider: A vSphere or ESXi administrator with VASA access to a FlashArray escalates toCVE-2023-36628 · Pure Storage FlashArray VASA providerHigh
- LangChain (recursive URL loader): SSRF — crawling proceeds to internal hostsCVE-2023-46229 · LangChain (recursive URL loader)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.