HIGH
NVDSUPPLY-CHAINCVE-2026-12772
2026-06-21
A security flaw in BerriAI litellm up to 1.82.2 allows remote manipulation, potentially leading to session expiration.
HIGH
NVDSUPPLY-CHAINCVE-2026-12773
2026-06-21
A weakness in BerriAI litellm up to 1.59.8 allows improper authentication, which can be exploited remotely.
HIGH
NVDSUPPLY-CHAINCVE-2026-12774
2026-06-21
A security vulnerability in BerriAI litellm up to 1.82.2 allows server-side request forgery, which can be exploited remotely.
HIGH
NVDSUPPLY-CHAINCVE-2026-12795
2026-06-21
A vulnerability in BerriAI litellm up to 1.82.2 allows remote execution of a manipulation that leads to missing authentication.
HIGH
NVDSUPPLY-CHAINCVE-2026-12796
2026-06-21
A vulnerability in BerriAI litellm up to 1.82.2 allows session expiration, exploitable remotely with publicly available exploits.
HIGH
NVDSUPPLY-CHAINCVE-2026-12797
2026-06-21
A security flaw in BerriAI litellm up to 1.82.5 allows remote manipulation of the prompt, leading to incorrect authorization.
HIGH
NVDSUPPLY-CHAINCVE-2026-55443
2026-06-22
LangChain framework has a vulnerability that allows disclosure of files outside the intended boundary when components receive path values from untrusted sources
HIGH
NVDSUPPLY-CHAINCVE-2026-41523
2026-06-22
Arbitrary code execution on the server via a malicious HuggingFace model.
HIGH
NVDSUPPLY-CHAINCVE-2026-47155
2026-06-22
vLLM's revision pinning controls do not consistently apply to all artifacts loaded for a model, allowing deployment of unpinned code.
HIGH
NVDSUPPLY-CHAINCVE-2026-48746
2026-06-22
Vulnerability in ASGI web servers and starlette's trust on those web servers enables authentication bypass of OpenAI API.
HIGH
NVDSUPPLY-CHAINCVE-2026-53923
2026-06-22
Integer truncation vulnerability in vLLM's GGUF dequantize kernels allows for information disclosure.
HIGH
NVDSUPPLY-CHAINCVE-2026-54232
2026-06-22
vulnerability to dependency confusion attack through a package on PyPI, allowing arbitrary code execution as root during Docker build and backdoor container ima
HIGH
NVDSUPPLY-CHAINCVE-2026-54233
2026-06-22
vLLM has a vulnerability that can lead to large memory usage, potentially causing denial of service.
HIGH
NVDSUPPLY-CHAINCVE-2026-54235
2026-06-22
vLLM has a vulnerability prior to version 0.23.1rc0 that can cause undefined behavior or CUDA errors, potentially crashing the inference worker.
HIGH
NVDSUPPLY-CHAINCVE-2026-54236
2026-06-22
A high-severity vulnerability was discovered in a large language model inference and serving engine, allowing an attacker to leak heap memory addresses through