Database/AI/ML frameworks & serving
TorchServe (gRPC 7070/7071): gRPC ports bound to all interfaces regardless of config
CVSS 8.2CVE-2024-35199AI/ML frameworks & servingcurated
Impact
gRPC ports bound to all interfaces regardless of config
Who can reach it
Unauthenticated network from a co-tenant or the internet
What to do
Patch and enforce bind-address at the pod/network policy layer, not in app config
References
Related entries
- Ollama (GGUF parser): Malformed 4-byte GGUF file crashes the server (two HTTP requests)CVE-2024-39720 · Ollama (GGUF parser)High
- vLLM: out-of-vocabulary stop_token_ids kill EngineCore and take the model server down until restartCVE-2026-100652 · vLLM (Rust HTTP/gRPC frontend, stop_token_ids validation)High
- GitLab AI Gateway: crafted model metadata redirects model requests and discloses Vertex or Bedrock credentialsCVE-2026-19889 · GitLab AI Gateway (Duo Agent Platform model metadata handling)High
- Docker Model Runner (vllm-metal backend): `trust_remote_code=True` set unconditionally, no sandboxCVE-2026-5817 · Docker Model Runner (vllm-metal backend)High
- GitLab AI Gateway: crafted inline flow config overrides the HTTP Host header and leaks Vertex credentialsCVE-2026-75871 · GitLab AI Gateway (Duo Agent Platform inline flow configuration)High
- Gradio: Command injectionCVE-2023-6572 · GradioHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.