HighVulnerability
CVE-2026-100308: Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-100308
- Published
- Record updated
Summary
CVE-2026-100308 affects the model loading component in Amazon GluonTS before 0.17.0. Deserialization of untrusted data may allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process, via a crafted serialized model directory.
Mitigation
Upgrade to version 0.17.0 or later.
Topics
Related items
- LowCVE-2026-107288: Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until…Similar attack · NVD/CVE Database
- LowOAuth grants pile up faster than you can review them. Here's how to keep up.Similar attack · BleepingComputer
- MediumPoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining BotnetSimilar attack · The Hacker News
- HighCVE-2026-93675: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an expected…Similar attack · NVD/CVE Database
- HighCVE-2026-105812 and CVE-2026-106032: Issue with Bedrock AgentCore Starter Toolkit - Import Agent Code Injection and SSRFSimilar attack · AWS Security Bulletins