Database/AI/ML frameworks & serving

LocalAI (`/models/apply`): SSRF and partial local file inclusion
CVSS 5.8CVE-2024-6095AI/ML frameworks & servingcurated
Impact
SSRF and partial local file inclusion
Who can reach it
Unauthenticated network
What to do
Upgrade past 2.15.0
References
Related entries
- LocalAI (`/models/apply`): Unauthenticated SSRF fetching arbitrary internal URLsCVE-2026-59707 · LocalAI (`/models/apply`)High
- NVIDIA NemoClaw: insufficiently protected credentials allow information disclosure and data tamperingCVE-2026-65087 · NVIDIA NemoClaw (credential storage)Medium
- Linux perf/x86/amd/uncore - memory leak in the events array: Per-CPU northbridge and last-level-cache uncore contextsCVE-2022-49784 · Linux perf/x86/amd/uncore - memory leak in the events arrayMedium
- PyTorch (flatbuffer loader): Out-of-bounds read parsing flatbuffer modelCVE-2024-31584 · PyTorch (flatbuffer loader)Medium
- vLLM: crafted request to the Gemma4 unified parser crashes the inference serverCVE-2026-103241 · vLLM (Gemma4UnifiedParser, rust/src/parser/src/unified/gemma4.rs)Medium
- Keras (HDF5 ExternalLink, incomplete fix): Arbitrary HDF5 file readCVE-2026-12480 · Keras (HDF5 ExternalLink, incomplete fix)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.