Database/AI/ML frameworks & serving
Pure Storage FlashArray key rotation logging (Rapid Data Locking): The Key Encryption Key is written to logs during
CVSS 5.1CVE-2025-2327AI/ML frameworks & servingcurated
Impact
The Key Encryption Key is written to logs during rotation when Rapid Data Locking is configured. Anyone who can read those logs - including whoever receives a support bundle - holds the key that protects data at rest on the array.
Who can reach it
Read access to FlashArray logs, or possession of a support bundle collected from an affected array with RDL enabled.
What to do
Upgrade Purity//FA to the fixed release, then rotate the KEK again on a patched version and destroy or recall any log set or support bundle collected while the flaw was present.
References
Related entries
- AutoGPT Platform: unbounded container logs fill the host disk and take the service downCVE-2025-32425 · AutoGPT Platform (container logging, no log size limit)Medium
- JupyterLab: stored XSS from javascript: URLs in extension metadata shown by Extension ManagerCVE-2026-67338 · JupyterLab Extension Manager (package metadata URL protocol validation)Medium
- TensorFlow Lite (flatbuffer models): Out-of-bounds via duplicate tensor indices in flatbuffer modelsCVE-2020-15211 · TensorFlow Lite (flatbuffer models)Medium
- Intel Extension for PyTorch: unsafe deserialization of untrusted data allows local privilege escalationCVE-2026-35502 · Intel Extension for PyTorch (untrusted deserialization)Medium
- diffusers (shard file loader): Path traversal in `_get_checkpoint_shard_files`CVE-2026-65920 · diffusers (shard file loader)Medium
- vLLM: derender endpoints process caller-supplied response objects before limits, exhausting CPU and memoryCVE-2026-71486 · vLLM OpenAI-compatible server (/v1/completions/derender and /v1/chat/completions/derender)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.