Database/AI/ML frameworks & serving
KubeAI (Ollama engine controller): Injection in `ollamaStartupProbeScript()`
CVSS 8.7CVE-2026-34940AI/ML frameworks & servingcurated
Impact
Injection in ollamaStartupProbeScript()
Who can reach it
Tenant-supplied model name in a Kubernetes AI operator
What to do
Upgrade to 0.23.2+; operator-plane compromise from tenant input
References
Related entries
- Xinference: model launch API executes attacker-supplied Python because trust_remote_code is always onCVE-2026-76841 · Xinference (Xorbits Inference) model loaders - trust_remote_codeHigh
- Ollama: model pull follows cross-host redirects, giving SSRF to internal and metadata endpointsCVE-2026-85180 · Ollama (tensor-layer blob download, cross-host redirect handling)High
- Axolotl: multipack patch loads Hugging Face base models with trust_remote_code=True, giving RCE on the training nodeCVE-2026-86169 · Axolotl (multipack patch path, trust_remote_code guard)High
- vLLM: rejected requests leak decode-worker metadata until the worker exhausts memoryCVE-2026-93436 · vLLM NIXL KV connector (decode-side metadata cleanup for rejected requests)High
- vLLM: negative token IDs in embeddings requests poison the CUDA context and wedge the engineCVE-2026-93592 · vLLM (/v1/embeddings and /pooling token ID validation)High
- vLLM: incomplete NIXL kv_transfer_params kills the decode engine with an uncaught KeyErrorCVE-2026-94622 · vLLM NIXL KV connector (kv_transfer_params metadata handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.