Attack Type

Auth Bypass

AI/ML platforms accumulate auth-bypass vulnerabilities at the same rate as other web software, but the blast radius is unusual: a bypass on an inference endpoint exposes expensive compute, paid model access, and potentially other tenants' conversations. Common patterns we see in NVD and GHSA include misconfigured JWT verification in self-hosted inference servers, missing authorization checks on admin routes in ML platforms, IDOR on prediction-history endpoints, and SSRF that escapes a sandboxed agent into the platform's internal network. Open-source AI platforms (MLflow, Gradio, LangServe, Ollama) have shipped multiple high-severity auth-bypass CVEs since 2023; CISA KEV has flagged at least one (the MLflow path-traversal/auth chain). Defenses: keep self-hosted AI platforms patched aggressively, require auth on all model endpoints, network-segment inference servers, and treat any exposed AI service as if compute-cost abuse will happen.

1476
Total CVEs
74
Pages
Page 54 of 74
Current
Severity CVE CVSS
HIGH GHSA-qjpc-qf9m-xwmr 8.8
HIGH GHSA-c29c-2q9c-pc86 -
MEDIUM GHSA-cqwv-9qjx-vxw2 5.3
HIGH GHSA-jvm4-4j77-39p6 -
HIGH GHSA-83w9-h5wv-j9xm -
MEDIUM GHSA-wv26-j37q-2g7p -
MEDIUM GHSA-p2fh-f5fc-44hr 6.5
HIGH GHSA-hw9r-h9mr-4jff 8.8
HIGH GHSA-mhq8-78pj-5j79 7.1
HIGH GHSA-mgq6-vr84-7m2j 8.0
HIGH GHSA-rggc-m335-3wvj -
HIGH CVE-2026-45499 8.8
HIGH CVE-2025-71380 8.8
HIGH CVE-2026-12196 -
LOW CVE-2026-14630 3.1
UNKNOWN CVE-2020-18325 -
UNKNOWN CVE-2020-25514 -
UNKNOWN CVE-2020-35276 -
HIGH CVE-2023-27098 7.5
CRITICAL CVE-2025-45949 9.8

Page 54 of 74