Database/AI/ML frameworks & serving

Kubeflow (Adversarial Robustness Toolbox component): Insecure deserialization in the Kubeflow model-loading component
CVSS 9.8CVE-2026-31229AI/ML frameworks & servingcurated
Impact
Insecure deserialization in the Kubeflow model-loading component
Who can reach it
Customer-supplied model evaluated by a robustness pipeline
What to do
Upgrade ART past 1.20.1
References
Related entries
- Adversarial Robustness Toolbox (Kubeflow component, robustness_evaluation_fgsm_pytorch.py): The ART Kubeflow evaluationCVE-2026-31230 · Adversarial Robustness Toolbox (Kubeflow component, robustness_evaluation_fgsm_pytorch.py)Critical
- llama.cpp (RPC `deserialize_tensor`): RPC backend skips all bounds validationCVE-2026-34159 · llama.cpp (RPC `deserialize_tensor`)Critical
- Apache OpenNLP: model archive manifest names any classpath class and runs its static initializerCVE-2026-42027 · Apache OpenNLP ExtensionLoader (model archive manifest.properties)Critical
- LiteLLM proxy: SQL injection in a database query pathCVE-2026-42208 · LiteLLM proxyCritical
- PyTorch Lightning: Reintroduced unsafe deserialization in 2.6.2CVE-2026-44484 · PyTorch LightningCritical
- LiteLLM proxy: Host-header parsing flaw in the proxyCVE-2026-49468 · LiteLLM proxyCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.