Database/AI/ML frameworks & serving
Pure Storage FlashArray authentication input validation: Malformed input during authentication takes the FlashArray
CVSS 8.7CVE-2025-0051AI/ML frameworks & servingcurated
Impact
Malformed input during authentication takes the FlashArray into a denial of service, before any credential is checked. Losing the array means every GPU node that mounts it loses its data path at once.
Who can reach it
Network reach to the FlashArray authentication surface. Pre-authentication, so no account is required.
What to do
Upgrade Purity//FA to the release named in Pure's security bulletin. Until patched, limit which networks can reach the array's login endpoints - this is reachable from anywhere the login prompt is.
References
Related entries
- Ollama: malformed base64 image data crashes the model runner via null pointer dereferenceCVE-2025-15514 · Ollama (multi-modal image handling in /api/chat)High
- skops (scikit-learn model sharing): Inconsistency in the `Operator` handling lets an untrusted model bypass the safeCVE-2025-54412 · skops (scikit-learn model sharing)High
- skops: Method-handling inconsistencyCVE-2025-54413 · skopsHigh
- SGLang: duplicate bootstrap_room values crash or hang the disaggregated schedulerCVE-2026-102634 · SGLang prefill/decode disaggregation (Mooncake KV transfer, bootstrap_room)High
- LightLLM: unbounded key-value writes on the NCCL control channel exhaust worker memoryCVE-2026-103042 · LightLLM NCCL KV-transfer control channel (exposed_set_value)High
- Mooncake transfer engine: zero-length handshake frame crashes the hosting inference processCVE-2026-104433 · Mooncake transfer engine (P2P handshake readString)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.