Database/AI/ML frameworks & serving
wandb SDK (`ArtifactManifestEntry.download`): Hash-handling weakness in artifact download integrity
CVSS 3.1CVE-2026-15605AI/ML frameworks & servingcurated
Impact
Hash-handling weakness in artifact download integrity
Who can reach it
Poisoned artifact in the registry
What to do
Upgrade the SDK in base images; weakens artifact-integrity guarantees for model supply chain
References
Related entries
- vLLM (prefix cache hash collisions): Crafted prompts collide hashesCVE-2025-25183 · vLLM (prefix cache hash collisions)Low
- vLLM (prefix cache): Prefix-cache timing side channel leaks other tenants' promptsCVE-2025-46570 · vLLM (prefix cache)Low
- vLLM: unvalidated bad_words token indices corrupt logits of other in-flight requestsCVE-2026-93989 · vLLM sampling parameters (bad_words token index validation)Low
- Langflow: authenticated user reaches eval() through component input options and runs code on the hostCVE-2026-101861 · Langflow schema.py (eval() on component input option values)Low
- mistral.rs: out-of-bounds read parsing GGUF token id metadata crashes the inference serverCVE-2026-75090 · mistral.rs GGUF tokenizer (convert_gguf_to_hf_tokenizer)Low
- Ollama: integer overflow in the GGUF v1 string reader when parsing a crafted model fileCVE-2026-86289 · Ollama GGUF decoder (readGGUFV1String in fs/ggml/gguf.go)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.