VulnWatch VulnWatch
← Back to dashboard
#

Data Leakage

77 entries

Every Data Leakage entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Low github

Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams

### Summary Ruby's JSON native C extension clears the consumed `JSON::ResumableParser` input buffer but leaves `state.start`, `state.cursor`, and `state.end` pointing into released storage. When `pa...

0.0
CVSS
11 hours ago
High nvd

CVE-2026-9130: IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows a

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collisio...

7.1
CVSS
2 days ago
Medium nvd

CVE-2026-47487: NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repos

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name...

Data Leakage triton mlflow
4.4
CVSS
3 days ago
High github

Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history

### Summary The **GET `/api/v1/upsert-history`** endpoint returns the **entire server-wide upsert history** (response size **>100MB**) instead of being scoped to the requesting user/tenant/workspace....

0.0
CVSS
3 days ago
Low github

MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure

### Summary `MessagePack::Buffer#clear` shifts out every chunk and returns its 4 KiB rmem page to the shared pool, but does not reset the buffer's rmem cursor (`rmem_last`, `rmem_end`, `rmem_owner`)....

0.0
CVSS
1 week ago
High nvd

CVE-2026-13442: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user inform...

Data Leakage langflow faiss
7.1
CVSS
1 week ago
High nvd

CVE-2026-66759: A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the pl

A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the...

7.1
CVSS
1 week ago
High github

PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments

## Summary PostCSS's `PreviousMap` parses the `/*# sourceMappingURL=PATH */` comment from any CSS string passed to `process()` and dereferences `PATH` against the local filesystem with no scheme, all...

7.5
CVSS
2 weeks ago
Low nvd

CVE-2026-44187: A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with

A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges,...

3.3
CVSS
2 weeks ago
Low osv

vLLM: Speech-to-text upload size limit is enforced after full UploadFile read

## Summary Current-head vLLM documents `VLLM_MAX_AUDIO_CLIP_FILESIZE_MB` as the maximum audio file size accepted by the speech-to-text APIs. The default is 25 MB. `vllm/envs.py` also describes files...

3.1
CVSS
3 weeks ago
Unknown rss_securityweek

In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint

Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach. The post In Other News: Iran...

3 weeks ago
High nvd

CVE-2026-47473: NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful ex

NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful exploit of this vulnerability might lead to data tampering, denial of service, and...

Data Leakage tensorrt llm
7.4
CVSS
3 weeks ago
High nvd

CVE-2026-47472: NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-

NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerabil...

7.8
CVSS
3 weeks ago
High nvd

CVE-2026-47471: NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a

NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow. A successful exploit of this vulnerability might le...

7.5
CVSS
3 weeks ago
Medium nvd

CVE-2026-24259: NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critic

NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to code execu...

Data Leakage tensorrt llm
6.4
CVSS
3 weeks ago
Medium nvd

CVE-2026-24234: NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-acces

NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause server-side request forgery. A successful exploit of...

6.8
CVSS
3 weeks ago
High nvd

CVE-2026-24233: NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization

NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrust...

8.4
CVSS
3 weeks ago
High nvd

CVE-2026-24229: NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker co

NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the Fas...

Data Leakage tensorrt llm
7.3
CVSS
3 weeks ago
Medium nvd

CVE-2026-24226: NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation

NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, data...

Data Leakage tensorrt llm
6.3
CVSS
3 weeks ago
Medium nvd

CVE-2026-47481: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass t

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerabilit...

6.5
CVSS
3 weeks ago
Medium osv

vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving

## Summary Integer truncation of tensor dimensions in vLLM's GGUF dequantize kernels (`csrc/quantization/gguf/gguf_kernel.cu`) causes partial tensor processing. The output tensor is allocated at full...

4.0
CVSS
3 weeks ago
Low osv

BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context

### Summary BentoML's `bentoml build` packaging workflow follows attacker-controlled symlinks inside the build context and copies the referenced file contents into the generated Bento artifact. If a...

3.1
CVSS
3 weeks ago
High nvd

CVE-2026-15574: A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorizat

A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain personally identifiable in...

7.5
CVSS
3 weeks ago
Unknown rss_securityweek

In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops

Other noteworthy stories that might have slipped under the radar: Abnormal AI sued by Anthropic, AssuranceAmerica data breach affects 7 million people, NSA brings back TAO. The post In Other News: DHS...

Data Leakage anthropic
4 weeks ago
Low osv

Langchain Community Vulnerable to XML External Entity (XXE) Attacks

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The vulnerability arises from the use of...

Data Leakage langchain-community
3.0
CVSS
1 month ago