Database/AI/ML frameworks & serving
vLLM (image error echo): Error path returns sensitive content on invalid image input
CVSS 9.8CVE-2026-22778AI/ML frameworks & servingcurated
Impact
Error path returns sensitive content on invalid image input
Who can reach it
Unauthenticated network to the multimodal endpoint
What to do
Upgrade past 0.14.1
References
Related entries
- Milvus (port 9091): Management port 9091 exposed by default enabling compromiseCVE-2026-26190 · Milvus (port 9091)Critical
- SGLang (multimodal ZMQ broker): Unauthenticated RCE via `pickle.loads()` on the ZMQ brokerCVE-2026-3059 · SGLang (multimodal ZMQ broker)Critical
- SGLang (encoder parallel disaggregation): Unauthenticated RCE via `pickle.loads()` in the disaggregation moduleCVE-2026-3060 · SGLang (encoder parallel disaggregation)Critical
- LiteLLM (MCP server creation): RCE via MCP server registrationCVE-2026-30623 · LiteLLM (MCP server creation)Critical
- Kubeflow (ART component): RCE in the robustness evaluation functionCVE-2026-31228 · Kubeflow (ART component)Critical
- Kubeflow (Adversarial Robustness Toolbox component): Insecure deserialization in the Kubeflow model-loading componentCVE-2026-31229 · Kubeflow (Adversarial Robustness Toolbox component)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.