Database/AI/ML frameworks & serving
vLLM (`load_from_url_async`): Bypass of the CVE-2026-24779 SSRF fix
CVSS 7.1CVE-2026-25960AI/ML frameworks & servingcurated
Impact
Bypass of the CVE-2026-24779 SSRF fix
Who can reach it
Unauthenticated request
What to do
Upgrade past 0.15.1. Third SSRF in the same connector — network-layer egress control is the only durable fix
References
Related entries
- picklescan: `scan_pytorch` bypass via forged magic numbersCVE-2026-53875 · picklescanHigh
- torchvision (GIF decoder): Out-of-bounds heap read in `read_from_tensor` GIF decodeCVE-2026-65918 · torchvision (GIF decoder)High
- MLflow: model version creation reads another user's run artifacts without READ permissionCVE-2026-69148 · MLflow tracking server (CreateModelVersion source run/model validation)High
- MLflow AI Gateway: unvalidated api_base in gateway secrets turns the proxy endpoint into an authenticated SSRFCVE-2026-71211 · MLflow AI Gateway (gateway secret auth_config.api_base, raw_proxy endpoint)High
- Hugging Face tokenizers: crafted tokenizer.json aborts the process while loading a BPE modelCVE-2026-85670 · Hugging Face tokenizers (BpeBuilder::build, BPE merge loading)High
- Jupyter Server: Referer header is logged unscrubbed, leaking auth tokens into server logsCVE-2026-86049 · Jupyter Server (5xx request logging in jupyter_server/log.py)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.