AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 1604 resultsllama_index: SQL injection in vector store integrations
CVE-2025-1793 jupyter_core: config hijack enables cross-user code exec
CVE-2025-30167 vLLM: input validation DoS crashes inference worker
CVE-2025-48944 vLLM: ReDoS crashes inference server via malformed regex
CVE-2025-48943 vLLM: DoS via malformed JSON schema guided param
CVE-2025-48942 vLLM: ReDoS in tool parser causes service outage
CVE-2025-48887 Gradio: unauthenticated file copy enables disk DoS
CVE-2025-48889 vLLM: image hash collision enables multimodal cache leakage
CVE-2025-46722 vLLM: timing side-channel leaks prompt cache data
CVE-2025-46570 Gradio: CORS origin bypass in ML UI handler
CVE-2025-5320 vllm: ReDoS in inference endpoints enables DoS
GHSA-j828-28rj-hfhp llama-index-cli: OS command injection enables RCE
CVE-2025-1753 label-studio-ml: PyTorch .pt deserialization RCE in YOLO loader
CVE-2025-5173 vLLM: RCE via exposed TCPStore in distributed inference
CVE-2025-47277 transformers: ReDoS in testing_utils causes DoS
CVE-2025-2099 Ollama: DoS via malicious manifest in /api/pull
CVE-2025-1975 Label Studio: XSS enables unauthorized actions via CSRF
CVE-2025-47783 llama_index: DoS via uncapped recursion in web reader
CVE-2025-1752 TensorFlow Serving: JSON recursion DoS on inference API
CVE-2025-0649 vLLM: pickle RCE in multi-node inference deployments
CVE-2025-30165 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert