🤖

AI/ML

slug: ai-ml

🛡 関連する脆弱性 24

ID タイトル
CVE-2026-47852 A local attacker on a multi-user host can pre-create the deterministic cache path and plant a...
CVE-2026-47851 Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
CVE-2026-72642 The native inference process that Elasticsearch uses to evaluate uploaded machine learning models...
CVE-2026-72742 DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field...
CVE-2026-71281 Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines...
CVE-2026-67428 Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
CVE-2026-67427 Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
CVE-2026-67425 Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
CVE-2026-12484 Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
CVE-2026-7755 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
CVE-2026-12773 A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function...
CVE-2026-47749 stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Versions prior to master-584-0a7ae07 are vulnerable to...
CVE-2026-47835 CVE-2026-47835 の脆弱性 (CVE-2026-47835)
CVE-2026-12191 deserialization の脆弱性 (CVE-2026-12191)
CVE-2026-5497 vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method
CVE-2026-44285 FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network prot...
CVE-2026-30950 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijack...
CVE-2026-2614 MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
CVE-2026-42302 openai-sdk の脆弱性 (CVE-2026-42302)
CVE-2026-42298 docker に コードインジェクション (CVE-2026-42298)
CVE-2026-44336 praison の脆弱性 (CVE-2026-44336)
CVE-2026-41512 gem に コードインジェクション (CVE-2026-41512)
CVE-2026-41497 praison に コマンドインジェクション (CVE-2026-41497)
CVE-2026-42208 KEV 【KEV】Berriai litellm に SQLインジェクション (CVE-2026-42208)

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →