Database/AI/ML frameworks & serving

SGLang (scheduler ROUTER socket): ROUTER socket binds `0.0.0.0` by default and `pickle.loads()` incoming messages
CVSS 9.8CVE-2026-7301AI/ML frameworks & servingcurated
Impact
ROUTER socket binds 0.0.0.0 by default and pickle.loads() incoming messages
Who can reach it
Unauthenticated network — default configuration is exploitable
What to do
Upgrade and override the bind address. The insecure default means an unmodified deployment is exposed
References
Related entries
- SGLang (custom logit processor): `dill.loads` on user objects when `--enable-custom-logit-processor` is setCVE-2026-7304 · SGLang (custom logit processor)Critical
- MLflow (mlflow server / mlflow ui, Model Registry): REMOTE FILE ACCESS on the host running the tracking and registryNCVD-2023-010-mlflow-mlflow-server-mlflow-ui-m · MLflow (mlflow server / mlflow ui, Model Registry)Critical
- ClearML API server: CSRF against the API serverCVE-2024-24593 · ClearML API serverCritical
- llama-cpp-python: RCE via Jinja2 template in a GGUF model's metadata (`Llama` class)CVE-2024-34359 · llama-cpp-pythonCritical
- Jupyter Server Proxy: Unauthenticated web access to a user's proxied processesCVE-2024-35225 · Jupyter Server ProxyCritical
- Langflow OSS: submitted components run arbitrary Python as root on the serverCVE-2026-12944 · IBM Langflow OSS (component code validation / sandbox)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.