Interactive filter
ML Stack CVE Filter
Pick the ML packages and runtimes you actually run and see only the CVEs that affect them. Every ID is checked against NVD. Filter by severity, fix availability, exploitation status and affected-version range, or paste a requirements.txt to auto-select.
130 CVEs across 20 packages · reviewed 2026-08.
Every CVE ID in this table was re-checked against the NVD API on 19 August 2026. That pass removed 45 entries: 9 whose IDs are not published in NVD at all (three of those were malformed variants such as CVE-2025-32434b), 3 that had been withdrawn by their CNA, and 33 whose NVD record describes an unrelated product. It corrected 44 CVSS base scores, re-attributed 6 entries to the correct package, and added 33 entries, 27 of them covering the inference-serving runtimes (Ollama, vLLM, llama.cpp). CVSS values here are the base score NVD publishes: NVD's own CVSS v3.1 analysis where one exists, otherwise the CNA's score. Those two can differ by more than a point - NVD scores the 2024 llama.cpp GGUF overflows 9.8 where Cisco Talos, the CNA, scored them 8.8 - so a scanner quoting CNA numbers will not always match this table. Affected and fixed version ranges come from the linked advisory and were NOT independently re-derived, so confirm the range against NVD or the vendor advisory before making a remediation decision. Some MLflow and Ray entries have no patched version upstream; those are mitigations-only.