Database/AI/ML frameworks & serving

SGLang (`/v1/rerank`): RCE via a malicious `tokenizer.chat_template` rendered as Jinja2
CVSS 9.8CVE-2026-5760AI/ML frameworks & servingcurated
Impact
RCE via a malicious tokenizer.chat_template rendered as Jinja2
Who can reach it
Customer-supplied model file — the chat template inside the model repo is the payload
What to do
Upgrade. Jinja chat templates are code; scanning the weights does not cover the tokenizer config
References
Related entries
- gitlab-mcp: unauthenticated SSE transport plus arbitrary file read leaks the GitLab tokenCVE-2026-61560 · @zereight/mcp-gitlab MCP server (SSE transport, upload_markdown file_path)Critical
- SGLang (scheduler ROUTER socket): ROUTER socket binds `0.0.0.0` by default and `pickle.loads()` incoming messagesCVE-2026-7301 · SGLang (scheduler ROUTER socket)Critical
- SGLang (custom logit processor): `dill.loads` on user objects when `--enable-custom-logit-processor` is setCVE-2026-7304 · SGLang (custom logit processor)Critical
- MLflow (mlflow server / mlflow ui, Model Registry): REMOTE FILE ACCESS on the host running the tracking and registryNCVD-2023-010-mlflow-mlflow-server-mlflow-ui-m · MLflow (mlflow server / mlflow ui, Model Registry)Critical
- ClearML API server: CSRF against the API serverCVE-2024-24593 · ClearML API serverCritical
- llama-cpp-python: RCE via Jinja2 template in a GGUF model's metadata (`Llama` class)CVE-2024-34359 · llama-cpp-pythonCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.