Database/AI/ML frameworks & serving
vLLM (MessageQueue / ZMQ): `pickle.loads` on socket data
CVE-2024-11041AI/ML frameworks & servingcurated
Impact
pickle.loads on socket data → unauthenticated RCE
Who can reach it
Unauthenticated network to the vLLM internal ZMQ socket, reachable by a co-tenant
What to do
Upgrade; bind ZMQ to loopback and enforce per-tenant network policy. Internal IPC sockets must never cross the tenant boundary
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.