Database/AI/ML frameworks & serving
joblib (`NumpyArrayWrapper.read_array`): Deserialization vulnerability in joblib 1.4.2
CVSS 7.5CVE-2024-34997AI/ML frameworks & servingcurated
Impact
Deserialization vulnerability in joblib 1.4.2
Who can reach it
Customer-supplied joblib artifact
What to do
Contested as intended pickle behavior; the real control is format policy, not a version bump
References
Related entries
- Jupyter Server (Windows): Unauthenticated attackers can leak the NTLM hash of the hostCVE-2024-35178 · Jupyter Server (Windows)High
- Ollama: File-existence disclosure via `api/create`CVE-2024-39719 · OllamaHigh
- Ollama: Path traversal in `api/push` discloses server filesystem layoutCVE-2024-39722 · OllamaHigh
- Ollama (`extractFromZipFile`): Zip-slip: archive members extracted outside the parent directoryCVE-2024-45436 · Ollama (`extractFromZipFile`)High
- BentoML (bundled Gradio app, multipart boundary handling): Appending a long run of characters to a multipart boundaryCVE-2024-9056 · BentoML (bundled Gradio app, multipart boundary handling)High
- Ollama (GGUF import): Crafted GGUF causes DoS on model createCVE-2025-0312 · Ollama (GGUF import)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.