Database/AI/ML frameworks & serving

SGLang (multimodal runtime): Unauthenticated path traversal
CVSS 9.1CVE-2026-7302AI/ML frameworks & servingcurated
Impact
Unauthenticated path traversal → arbitrary file write as the server process
Who can reach it
Unauthenticated network to the serving port
What to do
Upgrade; run serving processes non-root with read-only root filesystems
References
Related entries
- Ollama (GGUF model loader): Heap out-of-bounds read from an attacker-supplied GGUF via `/api/create`CVE-2026-7482 · Ollama (GGUF model loader)Critical
- TensorFlow (SavedModel protobuf): Mutating a SavedModel protobuf crashes or corrupts the serving processCVE-2020-15206 · TensorFlow (SavedModel protobuf)Critical
- Jupyter Server Proxy: Authentication weakness in proxied-process accessCVE-2024-28179 · Jupyter Server ProxyCritical
- vLLM (Mooncake): Unsafe deserialization over ZMQ/TCP bound to all interfacesCVE-2025-29783 · vLLM (Mooncake)Critical
- Keras (`utils.get_file`, tar extract): Path traversal on tar extractionCVE-2025-12060 · Keras (`utils.get_file`, tar extract)High
- llama.cpp (`gguf_init_from_file_impl`): Integer overflow in GGUF initCVE-2025-53630 · llama.cpp (`gguf_init_from_file_impl`)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.