Database/AI/ML frameworks & serving
vLLM (`MediaConnector`): SSRF, recurrence of CVE-2025-6242
CVE-2026-24779AI/ML frameworks & servingcurated
Impact
SSRF, recurrence of CVE-2025-6242
Who can reach it
Unauthenticated request with an attacker-supplied media URL
What to do
Upgrade to 0.14.1+; enforce IMDSv2 / metadata deny at the network layer
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.