Database/AI/ML frameworks & serving
vLLM (activation function loading): Assert-based security check bypass, unauthenticated
CVSS 7.5CVE-2026-41523AI/ML frameworks & servingcurated
Impact
Assert-based security check bypass, unauthenticated
Who can reach it
Unauthenticated network
What to do
Upgrade to 0.22.0+
References
Related entries
- NVIDIA Triton Inference Server: missing authorization lets an unauthenticated caller reach protected operationsCVE-2026-47625 · NVIDIA Triton Inference Server for Linux (authorization check)High
- Spring AI: predictable ONNX model cache path lets a local user plant a substitute model fileCVE-2026-47852 · Spring AI (ONNX model cache path)High
- MKP Kubernetes MCP server: unauthenticated log request exhausts server memoryCVE-2026-50125 · MKP (Kubernetes MCP server, get_resource pod-logs subresource)High
- llama.cpp: uncontrolled recursion in JSON-schema-to-grammar conversion crashes the serverCVE-2026-52130 · llama.cpp (common/json-schema-to-grammar.cpp)High
- Ollama (quantization engine): Unauthenticated remote information disclosure — reads and exfiltrates model dataCVE-2026-5757 · Ollama (quantization engine)High
- NVIDIA NemoClaw for Linux: installer downloads code without an integrity checkCVE-2026-65097 · NVIDIA NemoClaw for Linux (installation scripts)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.