Database/AI/ML frameworks & serving
Milvus: Unauthenticated DoS terminating service components
CVSS 7.5CVE-2026-69111AI/ML frameworks & servingcurated
Impact
Unauthenticated DoS terminating service components
Who can reach it
Unauthenticated network
What to do
Upgrade past 2.6.22
References
Related entries
- Milvus: Unauthenticated attacker exploits the server directlyCVE-2025-64513 · MilvusCritical
- JupyterLab: crafted SVG in the image viewer yields same-origin XSS and code execution on the serverCVE-2026-73415 · JupyterLab ImageViewer (packages/imageviewer/src/widget.ts blob URL handling)High
- BentoML 1.3.9 (bundled Gradio app, /login endpoint): The /login endpoint of the integrated Gradio app processes eachNCVD-2025-016-bentoml-1-3-9-bundled-gradio-app · BentoML 1.3.9 (bundled Gradio app, /login endpoint)High
- UpTrain: authenticated remote code execution via the checks and metadata parameters on /create_projectCVE-2025-27770 · UpTrain dashboard backend (/create_project endpoint)High
- UpTrain: authenticated remote code execution via the checks and metadata parameters on /add_promptsCVE-2025-27771 · UpTrain dashboard backend (/add_prompts endpoint)High
- UpTrain: authenticated remote code execution via the checks and metadata parameters on /new_runCVE-2025-27772 · UpTrain dashboard backend (/new_run endpoint)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.