Attack Type

Supply Chain

Supply chain attacks target the AI/ML software supply chain — compromised packages, poisoned model repositories, malicious dependencies, or tampered training data distributed through trusted channels.

471
Total CVEs
24
Pages
Page 23 of 24
Current
Severity CVE CVSS
MEDIUM CVE-2026-1839 6.5
MEDIUM GHSA-w6wx-jq6j-6mcj -
MEDIUM GHSA-2qrv-rc5x-2g2h -
MEDIUM GHSA-m34q-h93w-vg5x -
MEDIUM GHSA-42mx-vp8m-j7qh -
MEDIUM GHSA-3q42-xmxv-9vfr -
HIGH GHSA-vfw7-6rhc-6xxg -
MEDIUM GHSA-vjx8-8p7h-82gr -
HIGH GHSA-89gg-p5r5-q6r4 7.7
HIGH CVE-2026-3357 8.8
CRITICAL CVE-2026-39890 9.8
CRITICAL GHSA-2763-cj5r-c79m 9.7
HIGH GHSA-7437-7hg8-frrw -
MEDIUM GHSA-ccx3-fw7q-rr2r -
MEDIUM GHSA-3vvq-q2qc-7rmp -
HIGH GHSA-qx8j-g322-qj6m -
MEDIUM GHSA-w9j9-w4cp-6wgr -
MEDIUM GHSA-w8g9-x8gx-crmm -
LOW GHSA-4f8g-77mw-3rxc -
MEDIUM GHSA-67mf-f936-ppxf -

Page 23 of 24