StreamlitGHSA-vqwp-45wm-r9r5
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low3.6CVE-2026-10804 · Published Jun 4, 2026 · updated Jul 15, 2026
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| streamlit PyPI | < 1.53.1 | 1.53.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-327
- Also known as
- CVE-2026-10804, PYSEC-2026-212
- nvd.nist.gov/vuln/detail/CVE-2026-10804
- github.com/streamlit/streamlit/issues/14622
- github.com/streamlit/streamlit/pull/14635
- github.com/streamlit/streamlit/pull/15397
- github.com/streamlit/streamlit/commit/fec0f584dae9261abed16cad35b32922104bb933
- github.com/pypa/advisory-database/tree/main/vulns/streamlit/PYSEC-2026-212.yaml
- github.com/streamlit/streamlit
- vuldb.com/cve/CVE-2026-10804
- vuldb.com/submit/831508
- vuldb.com/vuln/368253
- vuldb.com/vuln/368253/cti
More Streamlit advisories
All Streamlit| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 25 | Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure) | Medium4.7 | 1.54.0 |
| Aug 122024 | Path traveral in Streamlit on windows | Medium5.9 | 1.37.0 |
| Jan 122024 | Minor fix to previous patch for CVE-2022-35918 | Medium5.3 | 1.30.0 |
| Mar 172023 | Streamlit publishes previously-patched Cross-site Scripting vulnerability | Medium5.9 | 0.81.0 |
| Aug 62022 | Streamlit directory traversal vulnerability | Medium6.5 | 1.11.1 |