Skip to content

Changes

Severity, score, summary, fixed-version and withdrawal changes to advisories after they were first listed, newest first. The advisory itself stays; its history is kept here.

DateAdvisoryChange
Sep 25Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows
GO-2026-5072
Severity: Unrated to High
Sep 25Grafana Loki Path Traversal - CVE-2021-36156 Bypass in github.com/grafana/loki
GO-2026-5115
Severity: Unrated to Medium
Sep 25Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows
GO-2026-5235
Severity: Unrated to Medium
Sep 25Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor in github.com/argoproj/argo-workflows
GO-2026-5462
Severity: Unrated to High
Sep 25Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go) in github.com/argoproj/argo-workflows
GO-2026-5527
Severity: Unrated to Medium
Sep 25Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows
GO-2026-5751
Severity: Unrated to High
Sep 25DQL injection via checkUserPassword GraphQL query in github.com/dgraph-io/dgraph
GO-2026-5837
Severity: Unrated to High
Sep 25PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass we
PYSEC-2026-3967
Severity: Unrated to High
Sep 25Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated before being joined to the dataset directory. Attackers can supply crafted file_name values with directory traversal
PYSEC-2026-3716
Severity: Unrated to Medium
Sep 25Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import in github.com/dgraph-io/dgraph
GO-2026-6261
Severity: Unrated to Critical
Sep 24A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. This also presented a Local File Disclosure vulnerability to any file readable by the webserver process.
Apache Airflow · PYSEC-2019-216
Severity: Unrated to Medium
Sep 24** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the read_pickle() function is documented as unsafe and it is the user's
pandas · PYSEC-2020-73
Severity: Unrated to Critical
Sep 24Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider: before 2.3.2.
Apache Airflow · PYSEC-2023-3
Severity: Unrated to High
Sep 24Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.
Apache Airflow · PYSEC-2023-136
Severity: Unrated to High
Sep 24Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp.
PyTorch · PYSEC-2024-250
Severity: Unrated to Medium
Sep 24Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability allows DAG authors to unintentionally or intentionally log sensitive configuration variables. Unauthorized users could access these logs, potentially exp
Apache Airflow · PYSEC-2024-182
Severity: Unrated to High
Sep 24Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnerable if it
Apache Arrow · PYSEC-2024-161
Severity: Unrated to Critical
Sep 24A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. The manipulation leads to memory corruption. An attack has to be approached locally. The ex
PyTorch · PYSEC-2025-197
Severity: Unrated to Low
Sep 24Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory traversal sequences or absolute paths. Attackers can provide c
Gradio · PYSEC-2026-2179
Severity: Unrated to High
Sep 24vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with
vLLM · PYSEC-2026-3985
Severity: Unrated to High

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.