Database/AI/ML frameworks & serving

Dagster: Vulnerability in Dagster Core prior to 1.13.1
CVSS 8.3CVE-2026-41490AI/ML frameworks & servingcurated
Impact
Vulnerability in Dagster Core prior to 1.13.1
Who can reach it
Network user of the orchestrator
What to do
Upgrade to 1.13.1+
References
Related entries
- Gitingest: prefix-only host validation lets crafted URLs leak GitHub tokens to attacker hostsCVE-2026-82289 · Gitingest (_validate_host git host allowlist)High
- TorchServe (gRPC 7070/7071): gRPC ports bound to all interfaces regardless of configCVE-2024-35199 · TorchServe (gRPC 7070/7071)High
- Ollama (GGUF parser): Malformed 4-byte GGUF file crashes the server (two HTTP requests)CVE-2024-39720 · Ollama (GGUF parser)High
- vLLM: out-of-vocabulary stop_token_ids kill EngineCore and take the model server down until restartCVE-2026-100652 · vLLM (Rust HTTP/gRPC frontend, stop_token_ids validation)High
- GitLab AI Gateway: crafted model metadata redirects model requests and discloses Vertex or Bedrock credentialsCVE-2026-19889 · GitLab AI Gateway (Duo Agent Platform model metadata handling)High
- Docker Model Runner (vllm-metal backend): `trust_remote_code=True` set unconditionally, no sandboxCVE-2026-5817 · Docker Model Runner (vllm-metal backend)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.