ML CVEs ml cves · vulnerability tracking upd. 2026-08
// reference archive
The CVEs in your ML stack.
A focused tracker for CVEs in ML and AI infrastructure. PyTorch, TensorFlow, ONNX, vLLM, llama.cpp, transformers, langchain, LlamaIndex, model registries, and the broader AI/ML supply chain — dated, sourced to NVD or vendor advisory.
Enter the archive →Latest entries
// index10 of 18 entries
AI Bill of Materials Tools: AIBOM Formats and Generators
toolsAI CVEs in CISA KEV: Ray, LiteLLM, and What's Missing
Vulnerability Tra…Inference Server CVEs: vLLM, Ollama, llama.cpp, Triton
Vulnerability Tra…MLflow CVEs: Why 2.14.1 Still Fails Your Scanner
Vulnerability Tra…Model File Format Security: Pickle, Safetensors, GGUF
Vulnerability Tra…ML Model CVE Tracking: How to Monitor Your AI Stack
GuidesMalicious Model File Detection: Auditing ML Models
ML SecurityML Vulnerability Scanner Software: Static vs Dynamic Tools
ToolsHugging Face Model Supply Chain Risk: Pickle Backdoors
supply-chainTensorFlow Security Vulnerabilities 2026: CVEs and Supply Chain
ML SecurityStart here
The reference pages this site keeps current, whatever is newest above.
- ML stack CVE filter Pick your packages, see only the CVEs that reach them.
- Unsafe model deserialization The pickle problem behind most ML supply-chain CVEs.
- PyTorch security and the loading path The verified entries, and the hardening that holds.
- Model file format security Pickle, .keras, GGUF, ONNX and safetensors compared.
- Inference server CVEs vLLM, Ollama, llama.cpp and Triton, and why they fail.
- Triaging an ML-stack CVE From "a scanner flagged it" to a defensible decision.
Independent, specialist, and free to read
ML CVEs publishes focused, sourced guides on a single topic. No paywall, no account, no ad tracking.
Subscribe
ML CVEs — in your inbox
CVEs in ML libraries, frameworks, and the AI/ML supply chain. Sent only when there is something worth sending.
No spam. Unsubscribe anytime.