Database/AI/ML frameworks & serving

SGLang (custom logit processor): `dill.loads` on user objects when `--enable-custom-logit-processor` is set
CVSS 9.8CVE-2026-7304AI/ML frameworks & servingcurated
Impact
dill.loads on user objects when --enable-custom-logit-processor is set → unauthenticated RCE
Who can reach it
Unauthenticated network to the serving port
What to do
Upgrade; never enable custom logit processors on a tenant-facing endpoint
References
Related entries
- MLflow (mlflow server / mlflow ui, Model Registry): REMOTE FILE ACCESS on the host running the tracking and registryNCVD-2023-010-mlflow-mlflow-server-mlflow-ui-m · MLflow (mlflow server / mlflow ui, Model Registry)Critical
- ClearML API server: CSRF against the API serverCVE-2024-24593 · ClearML API serverCritical
- llama-cpp-python: RCE via Jinja2 template in a GGUF model's metadata (`Llama` class)CVE-2024-34359 · llama-cpp-pythonCritical
- Jupyter Server Proxy: Unauthenticated web access to a user's proxied processesCVE-2024-35225 · Jupyter Server ProxyCritical
- Langflow OSS: submitted components run arbitrary Python as root on the serverCVE-2026-12944 · IBM Langflow OSS (component code validation / sandbox)Critical
- Transformers: LightGlue config re-enables trust_remote_code from the model repo, executing repo code at loadCVE-2026-5241 · Hugging Face Transformers 5.2.0 (LightGlue config loading, trust_remote_code propagation)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.