Database/AI/ML frameworks & serving

ChromaDB (Rust): Missing authorization validation
CVSS 8.8CVE-2026-8828AI/ML frameworks & servingcurated
Impact
Missing authorization validation → arbitrary read/write across collections
Who can reach it
Authenticated tenant
What to do
Upgrade
References
Related entries
- LangBot: debug WebSocket on 0.0.0.0:5401 accepts plugin registration with no key setCVE-2026-90938 · LangBot plugin runtime (langbot_plugin debug WebSocket on 0.0.0.0:5401)High
- SGLang: unauthenticated PUT /route poisons the KV transfer routing table in disaggregated modeCVE-2026-92972 · SGLang prefill bootstrap service (unauthenticated PUT /route)High
- vLLM OpenAI-compatible server (qwen3_coder tool-call parser): Code execution inside the serving process, which on a GPUNCVD-2025-017-vllm-openai-compatible-server-qw · vLLM OpenAI-compatible server (qwen3_coder tool-call parser)High
- vLLM (multimodal prompt embeddings, sparse tensor validation): This is the advisory saying the earlier fix did notNCVD-2026-043-vllm-multimodal-prompt-embedding · vLLM (multimodal prompt embeddings, sparse tensor validation)High
- MLflow (statsmodels flavor, MLFLOW_ALLOW_PICKLE_DESERIALIZATION guard): SECURITY CONTROL BYPASS LEADING TO RCE: theNCVD-2026-054-mlflow-statsmodels-flavor-mlflow · MLflow (statsmodels flavor, MLFLOW_ALLOW_PICKLE_DESERIALIZATION guard)High
- Pure Storage FlashArray authentication input validation: Malformed input during authentication takes the FlashArrayCVE-2025-0051 · Pure Storage FlashArray authentication input validationHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.