tessera Tech, tiled.
MON 05.10.2026 · 02:22 UTC EDITION T-2026-W41

DATA · LIVING REFERENCE · T-DATA-CVE

AI/ML CVE Severity Tracker

Security vulnerabilities affecting the AI software supply chain — the libraries and serving infrastructure that modern LLM applications depend on. We query the NIST National Vulnerability Database for CVEs mentioning RAG stacks, model loaders, and inference servers — langchain, llama-index, transformers, PyTorch, TensorFlow, vLLM, Ollama, Hugging Face, Gradio, Streamlit, ComfyUI, Triton, and ONNX — over the last 90 days. Insecure model deserialization, server-side request forgery, and authentication bypasses are recurring themes: AI dependencies are now a first-class attack surface.

Last updated: September 28, 2026 (UTC) · 120 advisories · Source: NIST NVD

CRITICAL 8 HIGH 55 MEDIUM 44 LOW 7
CVE CVSS Severity Affected Summary Published
CVE-2026-61732 10.0 CRITICAL ollama Decepticon is an autonomous hacking agent for red teams. 2026-09-24
CVE-2025-66455 9.8 CRITICAL pytorch LMDeploy is a toolkit for compressing, deploying, and serving large language models. 2026-09-18
CVE-2026-47627 9.8 CRITICAL triton NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. 2026-08-18
CVE-2026-68771 9.8 CRITICAL comfyui ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserializa 2026-07-31
CVE-2026-15976 9.8 CRITICAL huggingface SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of 2026-07-30
CVE-2026-63766 9.8 CRITICAL gradio GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into shell commands executed with shell=True. 2026-07-20
CVE-2026-59706 9.3 CRITICAL ollama mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url parameter. 2026-07-07
CVE-2026-58116 9.8 CRITICAL transformers LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code by supplying a malicious model path in the Chat or Training interfaces. 2026-06-30
CVE-2026-94627 7.5 HIGH vllm vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments. 2026-09-21
CVE-2026-94626 7.5 HIGH vllm vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. 2026-09-21
CVE-2026-94624 7.5 HIGH vllm vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. 2026-09-21
CVE-2026-94623 7.5 HIGH vllm vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deploy 2026-09-21
CVE-2026-94622 7.5 HIGH vllm vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. 2026-09-21
CVE-2026-33625 8.8 HIGH huggingface LMDeploy is a toolkit for compressing, deploying, and serving large language models. 2026-09-18
CVE-2026-93592 7.5 HIGH vllm vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. 2026-09-18
CVE-2026-93436 7.5 HIGH vllm vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. 2026-09-17
CVE-2026-92816 7.8 HIGH comfyui ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. 2026-09-16
CVE-2026-55253 7.7 HIGH langchain LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. 2026-09-14
CVE-2026-90553 7.8 HIGH vllm vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. 2026-09-12
CVE-2026-47625 7.5 HIGH triton NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. 2026-09-08
CVE-2026-16497 7.5 HIGH triton NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. 2026-09-08
CVE-2026-85180 7.5 HIGH ollama Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. 2026-09-03
CVE-2026-80047 7.8 HIGH transformers A vulnerability in Hugging Face Transformers (versions 4.57.0 to 5.16.1) allows remote Python files to be written to local disk without user consent when using GenerativePreTrainedModel.load_custom_generate(). 2026-09-01
CVE-2026-82288 7.5 HIGH gradio Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. 2026-08-28
CVE-2026-82275 7.5 HIGH gradio Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access to intended directories. 2026-08-28
CVE-2026-82268 7.5 HIGH gradio Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. 2026-08-28
CVE-2026-37237 7.5 HIGH vllm vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. 2026-08-28
CVE-2026-47852 7.5 HIGH onnx A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. 2026-08-27
CVE-2026-58474 8.8 HIGH huggingface whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename con 2026-08-26
CVE-2026-79784 8.8 HIGH pytorch Vocos instantiates a class named by a configuration file without restricting which class may be named. 2026-08-25
CVE-2026-76841 8.8 HIGH pytorch Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. 2026-08-24
CVE-2026-49114 7.1 HIGH onnx In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check. 2026-08-21
CVE-2026-72848 8.6 HIGH langchain SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. 2026-08-20
CVE-2026-15679 7.8 HIGH pytorch Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. 2026-08-20
CVE-2026-47629 7.5 HIGH triton NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. 2026-08-18
CVE-2026-47628 7.5 HIGH triton NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. 2026-08-18
CVE-2026-19594 8.1 HIGH streamlit Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segm 2026-08-12
CVE-2026-9081 7.1 HIGH ollama IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider. 2026-08-05
CVE-2026-9856 7.1 HIGH huggingface A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. 2026-08-02
CVE-2026-56673 7.5 HIGH comfyui ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. 2026-07-31
CVE-2026-56672 8.2 HIGH comfyui ComfyUI is a node-based diffusion model GUI, API, and backend. 2026-07-31
CVE-2026-56671 7.5 HIGH comfyui ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. 2026-07-31
CVE-2026-56670 8.2 HIGH comfyui ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. 2026-07-31
CVE-2026-65918 7.1 HIGH pytorch PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. 2026-07-23
CVE-2026-65315 7.5 HIGH ollama Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields in 2026-07-21
CVE-2026-12484 7.8 HIGH pytorch A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. 2026-07-19
CVE-2026-58659 7.8 HIGH pytorch PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. 2026-07-15
CVE-2026-47482 7.5 HIGH triton NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory after effective lifetime. 2026-07-14
CVE-2026-47480 7.5 HIGH triton NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. 2026-07-14
CVE-2026-47479 7.5 HIGH triton NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. 2026-07-14
CVE-2026-47478 7.5 HIGH triton NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file descriptor. 2026-07-14
CVE-2026-47477 7.5 HIGH triton NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. 2026-07-14
CVE-2026-47476 7.5 HIGH triton NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. 2026-07-14
CVE-2026-15685 7.5 HIGH ollama Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. 2026-07-13
CVE-2026-15574 7.5 HIGH vllm A flaw was found in the vllm-orchestrator-gateway component. 2026-07-13
CVE-2026-55405 7.6 HIGH langchain LangChain4j is a Java library for building LLM-powered applications on the JVM. 2026-07-10
CVE-2026-59806 7.4 HIGH gradio Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirect users to arbitrary URLs or perform client-side SSRF by supplying unvalidated HTTP/HTTPS URLs to the file_fetch() 2026-07-08
CVE-2026-55574 7.5 HIGH vllm vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. 2026-07-06
CVE-2026-54234 7.5 HIGH vllm vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. 2026-07-06
CVE-2026-14535 8.8 HIGH transformers In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsaf 2026-07-04
CVE-2025-71342 8.1 HIGH pytorch picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. 2026-07-04
CVE-2026-49119 7.5 HIGH gradio Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory tr 2026-07-01
CVE-2026-24264 7.5 HIGH triton NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highly compressed data. 2026-07-01
CVE-2026-100654 6.5 MEDIUM vllm vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST /v1/chat/completions endpoints but validates only that the values are integers, not that each token id is within the model voca 2026-09-26
CVE-2026-100653 6.5 MEDIUM vllm vLLM is an inference and serving engine for large language models. 2026-09-26
CVE-2026-100652 5.9 MEDIUM vllm vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC frontends, allowing out-of-vocabulary token IDs to reach MinTokensLogitsProcessor. 2026-09-26
CVE-2026-100651 6.5 MEDIUM vllm vLLM before 0.29.0 fails to enforce decoder prompt-length validation on the disaggregated serving endpoint /inference/v1/generate. 2026-09-26
CVE-2026-100650 6.5 MEDIUM vllm vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls (the VLLM_MAX_AUDIO_CLIP_FILESIZE_MB compressed-audio size cap, default 25 MB, and the per-modality --limit-mm-per-prom 2026-09-26
CVE-2026-100648 5.3 MEDIUM vllm vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing unauthenticated clients to bypass file size restrictions. 2026-09-26
CVE-2026-100647 5.3 MEDIUM vllm vLLM versions before 0.29.0 contain a denial-of-service vulnerability in the cache_salt parameter accepted on OpenAI-compatible and Anthropic API endpoints, which lacks maximum length validation and is processed on the single EngineCore sch 2026-09-26
CVE-2026-97869 4.1 MEDIUM langchain A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27. 2026-09-25
CVE-2026-85709 5.3 MEDIUM ollama LightRAG provides simple and fast retrieval-augmented generation. 2026-09-22
CVE-2026-94625 5.3 MEDIUM vllm vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. 2026-09-21
CVE-2026-94093 6.3 MEDIUM pytorch, huggingface A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0. 2026-09-20
CVE-2026-69147 6.5 MEDIUM vllm vLLM is an inference and serving engine for large language models. 2026-09-16
CVE-2026-57173 6.5 MEDIUM vllm vLLM is an inference and serving engine for large language models. 2026-09-16
CVE-2026-92365 4.3 MEDIUM vllm A vulnerability was found in vllm-project vllm up to 0.29.0. 2026-09-16
CVE-2026-92220 5.3 MEDIUM vllm A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. 2026-09-16
CVE-2026-90878 4.3 MEDIUM vllm A vulnerability was determined in vllm-project vLLM up to 0.27.1. 2026-09-15
CVE-2026-55093 6.1 MEDIUM tensorflow, onnx Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. 2026-09-14
CVE-2026-55832 6.1 MEDIUM tensorflow, onnx Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. 2026-09-14
CVE-2026-90555 6.5 MEDIUM vllm vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. 2026-09-12
CVE-2026-90554 6.2 MEDIUM vllm vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video input for NanoNemotronVL models. 2026-09-12
CVE-2026-86289 4.3 MEDIUM ollama A vulnerability was found in Ollama up to 0.31.1. 2026-09-07
CVE-2026-86288 6.3 MEDIUM triton A vulnerability has been found in ModelCloud GPTQModel up to 7.2.0. 2026-09-07
CVE-2026-82637 5.3 MEDIUM gradio browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths to save_recording_path, save_trace_path, 2026-08-30
CVE-2026-79785 5.9 MEDIUM pytorch, onnx X-AnyLabeling's model downloader disabled TLS certificate verification. 2026-08-25
CVE-2026-78684 5.3 MEDIUM vllm vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. 2026-08-25
CVE-2026-47630 5.5 MEDIUM triton NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. 2026-08-18
CVE-2026-47606 6.5 MEDIUM triton NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. 2026-08-18
CVE-2026-75093 4.3 MEDIUM onnx A security vulnerability has been detected in sonos tract up to 0.23.4. 2026-08-18
CVE-2026-75104 5.5 MEDIUM transformers Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. 2026-08-17
CVE-2026-73560 6.5 MEDIUM vllm vLLM is an inference and serving engine for large language models. 2026-08-17
CVE-2026-71486 4.3 MEDIUM vllm vLLM is an inference and serving engine for large language models. 2026-08-17
CVE-2026-73559 6.5 MEDIUM vllm vLLM is an inference and serving engine for large language models. 2026-08-13
CVE-2026-73558 5.3 MEDIUM vllm vLLM is an inference and serving engine for large language models. 2026-08-13
CVE-2026-73556 5.3 MEDIUM vllm vLLM is an inference and serving engine for large language models. 2026-08-13
CVE-2026-73555 5.3 MEDIUM vllm vLLM is an inference and serving engine for large language models. 2026-08-13
CVE-2026-27765 5.5 MEDIUM vllm Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring 3: User Applications may allow a denial of service. 2026-08-11
CVE-2026-19334 5.3 MEDIUM ollama A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. 2026-08-09
CVE-2026-47487 4.4 MEDIUM triton NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. 2026-08-04
CVE-2026-47481 6.5 MEDIUM triton NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. 2026-07-14
CVE-2026-44512 5.5 MEDIUM onnx Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. 2026-07-08
CVE-2026-55514 6.5 MEDIUM vllm vLLM is a library for LLM inference and serving. 2026-07-06
CVE-2026-55646 6.5 MEDIUM vllm vLLM is an inference and serving engine for large language models. 2026-07-06
CVE-2026-14647 4.3 MEDIUM onnx A weakness has been identified in onnx up to 1.21.x. 2026-07-04
CVE-2026-24266 5.9 MEDIUM triton NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. 2026-07-01
CVE-2026-100649 3.7 LOW vllm vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler subclass shadowing allows independent counter increments. 2026-09-26
CVE-2026-93989 3.1 LOW vllm vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). 2026-09-19
CVE-2026-93841 3.7 LOW vllm, triton vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without bounds checking against vocabulary size. 2026-09-18
CVE-2026-93840 3.7 LOW vllm vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). 2026-09-18
CVE-2026-90713 3.3 LOW vllm A security flaw has been discovered in vllm-project vLLM up to 0.29.0. 2026-09-14
CVE-2026-63632 3.3 LOW onnx Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. 2026-08-18
CVE-2026-14742 3.1 LOW langchain A vulnerability was determined in langchain-ai langgraph up to 1.2.4. 2026-07-05
CVE-2026-62997 — UNKNOWN pytorch Kedro-Datasets provides data connectors for Kedro. 2026-09-16
CVE-2026-73557 — UNKNOWN vllm vLLM is an inference and serving engine for large language models. 2026-08-13
CVE-2026-35502 — UNKNOWN pytorch Deserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 within Ring 3: User Applications may allow an escalation of privilege. 2026-08-11
CVE-2026-24693 — UNKNOWN pytorch Protection mechanism failure for some Intel(R) oneCCL Bindings for PyTorch before version v2.8.0 within Ring 3: User Applications may allow an escalation of privilege. 2026-08-11
CVE-2026-21387 — UNKNOWN pytorch Protection mechanism failure for some Intel(R) LLM Library for PyTorch within Ring 3: User Applications may allow an escalation of privilege. 2026-08-11
CVE-2026-20728 — UNKNOWN tensorflow Protection mechanism failure for some Intel Extension for TensorFlow software before version 2.15.0.3 within Ring 3: User Applications may allow an escalation of privilege. 2026-08-11

Related: Prompt injection · Jailbreak · AI safety · Software coverage · Policy coverage

Data is mirrored from the public NIST NVD 2.0 API and refreshed weekly. Severity and CVSS reflect the highest score recorded across CVSS v3.x metrics. This page is a reference aid, not security advice; always consult the upstream advisory.