Database/AI/ML frameworks & serving

LiteLLM (JWT auth): Auth bypass when `enable_jwt_auth` is set
CVSS 9.1CVE-2026-35030AI/ML frameworks & servingcurated
Impact
Auth bypass when enable_jwt_auth is set
Who can reach it
Unauthenticated network
What to do
Upgrade to 1.83.0+
References
Related entries
- vLLM: ASGI request handling lets callers bypass API-key authentication on the OpenAI endpointsCVE-2026-48746 · vLLM OpenAI-compatible API server (AuthenticationMiddleware)Critical
- SGLang (multimodal runtime): Unauthenticated path traversalCVE-2026-7302 · SGLang (multimodal runtime)Critical
- Ollama (GGUF model loader): Heap out-of-bounds read from an attacker-supplied GGUF via `/api/create`CVE-2026-7482 · Ollama (GGUF model loader)Critical
- TensorFlow (SavedModel protobuf): Mutating a SavedModel protobuf crashes or corrupts the serving processCVE-2020-15206 · TensorFlow (SavedModel protobuf)Critical
- Jupyter Server Proxy: Authentication weakness in proxied-process accessCVE-2024-28179 · Jupyter Server ProxyCritical
- vLLM (Mooncake): Unsafe deserialization over ZMQ/TCP bound to all interfacesCVE-2025-29783 · vLLM (Mooncake)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.