Database/AI/ML frameworks & serving
Ollama (`extractFromZipFile`): Zip-slip: archive members extracted outside the parent directory
CVSS 7.5CVE-2024-45436AI/ML frameworks & servingcurated
Impact
Zip-slip: archive members extracted outside the parent directory
Who can reach it
Customer-supplied model archive
What to do
Upgrade past 0.1.47
References
Related entries
- BentoML (bundled Gradio app, multipart boundary handling): Appending a long run of characters to a multipart boundaryCVE-2024-9056 · BentoML (bundled Gradio app, multipart boundary handling)High
- Ollama (GGUF import): Crafted GGUF causes DoS on model createCVE-2025-0312 · Ollama (GGUF import)High
- NVIDIA Triton (Python backend): Information disclosure from the Python backendCVE-2025-23320 · NVIDIA Triton (Python backend)High
- vLLM (weight loading): `hf_model_weights_iterator` uses `torch.load` without `weights_only`CVE-2025-24357 · vLLM (weight loading)High
- vLLM (ZeroMQ): DoS and data exposure over ZeroMQCVE-2025-30202 · vLLM (ZeroMQ)High
- vLLM (HTTP GET): Single HTTP GET crashes the serverCVE-2025-48956 · vLLM (HTTP GET)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.