Database/AI/ML frameworks & serving
Ray (dashboard DELETE endpoints): Browser-origin protection covers POST/PUT but not DELETE
CVSS 5.9CVE-2026-27482AI/ML frameworks & servingcurated
Impact
Browser-origin protection covers POST/PUT but not DELETE; key DELETE endpoints unauthenticated
Who can reach it
Malicious page visited by an operator with dashboard access
What to do
Upgrade past 2.53.0
References
Related entries
- LocalAI (`/models/apply`): SSRF and partial local file inclusionCVE-2024-6095 · LocalAI (`/models/apply`)Medium
- NVIDIA NemoClaw: insufficiently protected credentials allow information disclosure and data tamperingCVE-2026-65087 · NVIDIA NemoClaw (credential storage)Medium
- Linux perf/x86/amd/uncore - memory leak in the events array: Per-CPU northbridge and last-level-cache uncore contextsCVE-2022-49784 · Linux perf/x86/amd/uncore - memory leak in the events arrayMedium
- PyTorch (flatbuffer loader): Out-of-bounds read parsing flatbuffer modelCVE-2024-31584 · PyTorch (flatbuffer loader)Medium
- vLLM: crafted request to the Gemma4 unified parser crashes the inference serverCVE-2026-103241 · vLLM (Gemma4UnifiedParser, rust/src/parser/src/unified/gemma4.rs)Medium
- Keras (HDF5 ExternalLink, incomplete fix): Arbitrary HDF5 file readCVE-2026-12480 · Keras (HDF5 ExternalLink, incomplete fix)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.