Database/AI/ML frameworks & serving
vLLM (`MediaConnector`): SSRF, recurrence of CVE-2025-6242
CVSS 7.1CVE-2026-24779AI/ML frameworks & servingcurated
Impact
SSRF, recurrence of CVE-2025-6242
Who can reach it
Unauthenticated request with an attacker-supplied media URL
What to do
Upgrade to 0.14.1+; enforce IMDSv2 / metadata deny at the network layer
References
Related entries
- vLLM (`load_from_url_async`): Bypass of the CVE-2026-24779 SSRF fixCVE-2026-25960 · vLLM (`load_from_url_async`)High
- picklescan: `scan_pytorch` bypass via forged magic numbersCVE-2026-53875 · picklescanHigh
- torchvision (GIF decoder): Out-of-bounds heap read in `read_from_tensor` GIF decodeCVE-2026-65918 · torchvision (GIF decoder)High
- MLflow: model version creation reads another user's run artifacts without READ permissionCVE-2026-69148 · MLflow tracking server (CreateModelVersion source run/model validation)High
- MLflow AI Gateway: unvalidated api_base in gateway secrets turns the proxy endpoint into an authenticated SSRFCVE-2026-71211 · MLflow AI Gateway (gateway secret auth_config.api_base, raw_proxy endpoint)High
- Hugging Face tokenizers: crafted tokenizer.json aborts the process while loading a BPE modelCVE-2026-85670 · Hugging Face tokenizers (BpeBuilder::build, BPE merge loading)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.