Attack Type

Auth Bypass

AI/ML platforms accumulate auth-bypass vulnerabilities at the same rate as other web software, but the blast radius is unusual: a bypass on an inference endpoint exposes expensive compute, paid model access, and potentially other tenants' conversations. Common patterns we see in NVD and GHSA include misconfigured JWT verification in self-hosted inference servers, missing authorization checks on admin routes in ML platforms, IDOR on prediction-history endpoints, and SSRF that escapes a sandboxed agent into the platform's internal network. Open-source AI platforms (MLflow, Gradio, LangServe, Ollama) have shipped multiple high-severity auth-bypass CVEs since 2023; CISA KEV has flagged at least one (the MLflow path-traversal/auth chain). Defenses: keep self-hosted AI platforms patched aggressively, require auth on all model endpoints, network-segment inference servers, and treat any exposed AI service as if compute-cost abuse will happen.

557
Total CVEs
28
Pages
Page 21 of 28
Current
Severity CVE CVSS
HIGH CVE-2026-41273 8.2
HIGH CVE-2026-41275 7.5
CRITICAL CVE-2026-41276 9.8
HIGH CVE-2026-41277 8.8
HIGH CVE-2026-41278 7.5
MEDIUM CVE-2026-6393 4.3
CRITICAL GHSA-r75f-5x8p-qvmc -
HIGH CVE-2026-40068 -
MEDIUM CVE-2026-41481 6.5
LOW CVE-2026-41488 3.1
HIGH GHSA-v4p8-mg3p-g94g -
MEDIUM GHSA-7jm2-g593-4qrc -
MEDIUM GHSA-qrp5-gfw2-gxv4 -
MEDIUM GHSA-h2vw-ph2c-jvwf -
LOW GHSA-j4c5-89f5-f3pm -
LOW GHSA-xrq9-jm7v-g9h7 -
LOW GHSA-57r2-h2wj-g887 -
MEDIUM GHSA-72q8-jcmc-97wx -
LOW GHSA-v8qf-fr4g-28p2 -
MEDIUM GHSA-2xcp-x87w-q377 -

Page 21 of 28