Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-v68g-wm8c-6x7j: transformers has a Deserialization of Untrusted Data vulnerability

Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.

ghsa
#vulnerability#git

transformers has a Deserialization of Untrusted Data vulnerability

Critical severity GitHub Reviewed Published Dec 20, 2023 to the GitHub Advisory Database • Updated Dec 20, 2023

ghsa: Latest News

GHSA-rm76-4mrf-v9r8: vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache