Database/AI/ML frameworks & serving

SGLang (`replay_request_dump.py`): Insecure `pickle.load()` on a `.pkl` dump
CVSS 7.8CVE-2026-3989AI/ML frameworks & servingcurated
Impact
Insecure pickle.load() on a .pkl dump
Who can reach it
Customer-supplied dump file replayed by an operator during debugging
What to do
Upgrade; operator tooling that ingests tenant artifacts is a privilege-escalation path into the provider plane
References
Related entries
- llama.cpp (`llama_batch_init`): Integer overflow from unchecked multiplicationCVE-2026-43627 · llama.cpp (`llama_batch_init`)High
- HuggingFace transformers: Critical RCE in all versions before 5.3.0CVE-2026-4372 · HuggingFace transformersHigh
- stable-diffusion.cpp: Memory-safety flaw in model loadingCVE-2026-47749 · stable-diffusion.cppHigh
- PyTorch Lightning (`_load_state`): RCE by importing and executing classes named in the checkpointCVE-2026-58659 · PyTorch Lightning (`_load_state`)High
- NVIDIA Megatron Bridge: deserialization of untrusted checkpoints or configs gives code executionCVE-2026-61750 · NVIDIA Megatron BridgeHigh
- NVIDIA NemoClaw: OS command injection in the status and logs plugin commandsCVE-2026-65089 · NVIDIA NemoClaw for Linux (status and logs plugin commands)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.