Database/AI/ML frameworks & serving
picklescan: ZIP manipulation crashes the scanner (scan bypass by DoS)
CVSS 6.5CVE-2025-1944AI/ML frameworks & servingcurated
Impact
ZIP manipulation crashes the scanner (scan bypass by DoS)
Who can reach it
Customer-supplied model archive
What to do
Upgrade to 0.0.23+; fail-closed on scanner crash
References
Related entries
- picklescan: Misses `idlelib.pyshell.ModifiedInterpreter.runcode` gadgetCVE-2025-71340 · picklescanHigh
- picklescan: Misses `idlelib.run.Executive.runcode` gadgetCVE-2025-71342 · picklescanHigh
- picklescan: Improper input validation lets a crafted pickle evade scanningCVE-2025-10155 · picklescanHigh
- picklescan: `scan_pytorch` bypass via forged magic numbersCVE-2026-53875 · picklescanHigh
- vLLM (`/v1/completions` guided decoding): Invalid `json_schema` kills the serverCVE-2025-48942 · vLLM (`/v1/completions` guided decoding)Medium
- vLLM: unbounded frame count in video/jpeg base64 data URLs crashes the server with OOMCVE-2026-34755 · vLLM OpenAI-compatible API server (video/jpeg base64 multimodal path)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.