Attack Type

Auth Bypass

AI/ML platforms accumulate auth-bypass vulnerabilities at the same rate as other web software, but the blast radius is unusual: a bypass on an inference endpoint exposes expensive compute, paid model access, and potentially other tenants' conversations. Common patterns we see in NVD and GHSA include misconfigured JWT verification in self-hosted inference servers, missing authorization checks on admin routes in ML platforms, IDOR on prediction-history endpoints, and SSRF that escapes a sandboxed agent into the platform's internal network. Open-source AI platforms (MLflow, Gradio, LangServe, Ollama) have shipped multiple high-severity auth-bypass CVEs since 2023; CISA KEV has flagged at least one (the MLflow path-traversal/auth chain). Defenses: keep self-hosted AI platforms patched aggressively, require auth on all model endpoints, network-segment inference servers, and treat any exposed AI service as if compute-cost abuse will happen.

1472
Total CVEs
74
Pages
Page 39 of 74
Current
Severity CVE CVSS
HIGH GHSA-rh39-9c67-59mh 8.1
CRITICAL GHSA-892r-p3jq-jp24 9.8
CRITICAL GHSA-x8cv-xmq7-p8xp 9.8
HIGH GHSA-rjvw-7vvw-549v 7.2
CRITICAL GHSA-fq2m-6wqh-x44g 9.8
CRITICAL GHSA-j4hj-7hfh-g2f4 9.8
HIGH GHSA-vxgj-xg5c-p4h7 8.5
CRITICAL GHSA-4869-x4pr-q22x 9.8
HIGH GHSA-p4pj-vh7h-6cqh 7.5
CRITICAL GHSA-x227-pf99-vffg 9.8
MEDIUM GHSA-6h9p-93hq-q7h6 6.5
HIGH GHSA-w6h2-fr4q-xvxv 8.8
HIGH GHSA-v847-hxxw-3pxg 7.8
HIGH GHSA-63v4-w882-g4x2 8.8
HIGH GHSA-fc26-m9pf-v56q 8.6
HIGH GHSA-qvpf-j64c-jmhr 8.3
HIGH GHSA-5qw8-f2g9-ff29 8.2
HIGH GHSA-vmf9-xx9w-86wx 8.3
HIGH GHSA-8579-rgg5-ph2m 8.8
MEDIUM GHSA-35w5-pcw4-jx94 4.3

Page 39 of 74