Skip to content
StreamlitGHSA-vqwp-45wm-r9r5

Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission

Low3.6CVE-2026-10804 · Published Jun 4, 2026 · updated Jul 15, 2026

A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.

GitHub advisory

Affected versions

PackageAffectedFixed in
streamlit
PyPI
< 1.53.11.53.1
Details and references

More Streamlit advisories

All Streamlit
Advisory
Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)
Medium4.7Mar 25
Path traveral in Streamlit on windows
Medium5.9Aug 12, 2024
Minor fix to previous patch for CVE-2022-35918
Medium5.3Jan 12, 2024
Streamlit publishes previously-patched Cross-site Scripting vulnerability
Medium5.9Mar 17, 2023
Streamlit directory traversal vulnerability
Medium6.5Aug 6, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.