Database/AI/ML frameworks & serving
Ray Dashboard: Path traversal in the dashboard static-file handler (port 8265)
CVSS 7.5CVE-2026-32981AI/ML frameworks & servingcurated
Impact
Path traversal in the dashboard static-file handler (port 8265)
Who can reach it
Unauthenticated network
What to do
Upgrade past 2.8.1
References
Related entries
- LangChain: prompt config files are loaded from unvalidated paths, letting a caller read arbitrary host filesCVE-2026-34070 · LangChain langchain-core prompt loading (load_prompt / load_prompt_from_config)High
- vLLM: unbounded media download from user-supplied URLs exhausts inference server memoryCVE-2026-37237 · vLLM multimodal input fetcher (`AsyncMediaIO.fetch_audio` / `fetch_image`)High
- vLLM (activation function loading): Assert-based security check bypass, unauthenticatedCVE-2026-41523 · vLLM (activation function loading)High
- NVIDIA Triton Inference Server: missing authorization lets an unauthenticated caller reach protected operationsCVE-2026-47625 · NVIDIA Triton Inference Server for Linux (authorization check)High
- Spring AI: predictable ONNX model cache path lets a local user plant a substitute model fileCVE-2026-47852 · Spring AI (ONNX model cache path)High
- MKP Kubernetes MCP server: unauthenticated log request exhausts server memoryCVE-2026-50125 · MKP (Kubernetes MCP server, get_resource pod-logs subresource)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.