Database/AI/ML frameworks & serving
MLflow (pyfunc tar extraction): Arbitrary file write from crafted tar entries
CVSS 9.1CVE-2025-15031AI/ML frameworks & servingcurated
Impact
Arbitrary file write from crafted tar entries
Who can reach it
Customer-supplied model archive
What to do
Upgrade
References
Related entries
- NVIDIA Triton (HTTP server): Attacker can start a reverse shell from the HTTP serverCVE-2025-23317 · NVIDIA Triton (HTTP server)Critical
- SGLang (expert-parallel backup ZMQ PULL): Unauthenticated, unvalidated deserialization on a routable interfaceCVE-2026-14890 · SGLang (expert-parallel backup ZMQ PULL)Critical
- LiteLLM (JWT auth): Auth bypass when `enable_jwt_auth` is setCVE-2026-35030 · LiteLLM (JWT auth)Critical
- vLLM: ASGI request handling lets callers bypass API-key authentication on the OpenAI endpointsCVE-2026-48746 · vLLM OpenAI-compatible API server (AuthenticationMiddleware)Critical
- SGLang (multimodal runtime): Unauthenticated path traversalCVE-2026-7302 · SGLang (multimodal runtime)Critical
- Ollama (GGUF model loader): Heap out-of-bounds read from an attacker-supplied GGUF via `/api/create`CVE-2026-7482 · Ollama (GGUF model loader)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.