Attack Type

Data Extraction

Data extraction attacks target the information processed or memorised by AI/ML systems. They take three main forms. First, training-data extraction: large language models can memorise verbatim spans of their training corpus, and an attacker who crafts the right prompts can pull back PII, API keys, or copyrighted text — a result demonstrated against GPT-2 by Carlini et al. and reproduced against several production models. Second, model extraction: by repeatedly querying a hosted model and observing outputs, an attacker can reconstruct enough behaviour to clone proprietary fine-tunes. Third, system-prompt and conversation leakage: indirect prompt injection or insecure logging can leak the application's instructions and other users' conversations. Multi-tenant inference platforms (vLLM, Triton, hosted APIs) and RAG systems are particularly exposed. Defenses: output filtering, differential privacy in training, rate limits, and strict tenant isolation.

952
Total CVEs
48
Pages
Page 47 of 48
Current
Severity CVE CVSS
CRITICAL CVE-2026-58046 9.9
HIGH CVE-2026-12942 7.5
HIGH CVE-2026-14538 7.7
HIGH GHSA-p7w7-4929-vpj5 7.5
CRITICAL CVE-2026-69084 10.0
CRITICAL CVE-2026-69085 10.0
UNKNOWN CVE-2026-69257 -
HIGH CVE-2026-70485 7.1
MEDIUM CVE-2026-70480 4.1
MEDIUM CVE-2026-54020 6.3
HIGH CVE-2026-6639 7.5
MEDIUM CVE-2026-7646 6.5
MEDIUM CVE-2026-7657 6.5
HIGH CVE-2026-8183 7.7
HIGH CVE-2026-64636 7.7
UNKNOWN CVE-2026-72750 -
UNKNOWN CVE-2026-72766 -
MEDIUM CVE-2026-48762 5.4
UNKNOWN CVE-2026-73484 -
CRITICAL CVE-2026-73487 -

Page 47 of 48