github.com/huggingface/diffusers
Submitted 8/4/2026, 10:28:00 AM · Status: ok
Risk grade
F
100 / 100
Findings
2710
4 critical74 high2571 medium60 low1 info0 on CISA KEV0ATT&CK
Showing 2,710 of 2,710 findings
Findings
- h11 accepts some malformed Chunked-Encoding bodiesgrypeCVE-2025-43859EPSS 0.6%
- PyTorch: `torch.load` with `weights_only=True` leads to remote code executiongrypeCVE-2025-32434EPSS 1.9%
- h11: h11 accepts some malformed Chunked-Encoding bodiesh11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since explo…trivyCVE-2025-43859
- PyTorch is a Python package that provides tensor computation with stro ...PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.…trivyCVE-2025-32434
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)grypeCVE-2026-69244
- AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bombgrypeCVE-2025-69223EPSS 0.5%
- Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)grypeCVE-2026-21441EPSS 2.7%
- Deserialization of Untrusted Data in Hugging Face TransformersgrypeCVE-2024-11394EPSS 2.4%
- Deserialization of Untrusted Data in Hugging Face TransformersgrypeCVE-2024-11393EPSS 2.9%
- Deserialization of Untrusted Data in Hugging Face TransformersgrypeCVE-2024-11393EPSS 2.9%
- Deserialization of Untrusted Data in Hugging Face TransformersgrypeCVE-2024-11393EPSS 2.9%
- Deserialization of Untrusted Data in Hugging Face TransformersgrypeCVE-2024-11392EPSS 7.1%
- Deserialization of Untrusted Data in Hugging Face TransformersgrypeCVE-2024-11392EPSS 7.1%
- Deserialization of Untrusted Data in Hugging Face TransformersgrypeCVE-2024-11392EPSS 7.1%
- Deserialization of Untrusted Data in Hugging Face TransformersgrypeCVE-2024-11394EPSS 2.4%
- Deserialization of Untrusted Data in Hugging Face TransformersgrypeCVE-2024-11394EPSS 2.4%
- Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom componentsgrypeCVE-2026-44513EPSS 0.9%
- Diffusers: TOCTOU Trust Remote Code BypassgrypeCVE-2026-45804EPSS 0.3%
- HuggingFace transformers vulnerable to remote code executiongrypeCVE-2026-4372EPSS 0.5%
- HuggingFace transformers vulnerable to remote code executiongrypeCVE-2026-4372EPSS 0.5%
- HuggingFace transformers vulnerable to remote code executiongrypeCVE-2026-4372EPSS 0.5%
- huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading PathgrypeCVE-2026-5241EPSS 0.5%
- huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading PathgrypeCVE-2026-5241EPSS 0.5%
- huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading PathgrypeCVE-2026-5241EPSS 0.5%
- huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading PathgrypeCVE-2026-5241EPSS 0.5%
- Sentencepiece has a a heap overflow issuegrypeCVE-2026-1260EPSS 0.2%
- Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``grypeCVE-2025-62727EPSS 0.6%
- Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoSgrypeCVE-2026-54283EPSS 0.4%
- Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on WindowsgrypeCVE-2026-48818EPSS 0.4%
- urllib3 allows an unbounded number of links in the decompression chaingrypeCVE-2025-66418EPSS 0.7%
- urllib3 streaming API improperly handles highly compressed datagrypeCVE-2025-66471EPSS 0.7%
- urllib3: Sensitive headers forwarded across origins in proxied low-level redirectsgrypeCVE-2026-44431EPSS 0.3%
- os.system() runs a string through the shell — command injection if any part is influenced by input. Use subprocess with an argv list. (Apache-2.0.)os.system() runs a string through the shell — command injection if any part is influenced by input. Use subprocess with an argv list. (Apache-2.0.)semgrepexamples/community/adaptive_mask_inpainting.py:192
- subprocess invoked through the shell (shell=True) or with a command string that is interpolated/concatenated/.split() instead of a fixed argv list — command injection risk. Pass a literal argv list ansubprocess invoked through the shell (shell=True) or with a command string that is interpolated/concatenated/.split() instead of a fixed argv list — command injection risk. Pass a literal argv list and shell=False. (First-party socbox; Apache-2.0.)semgreputils/get_modified_files.py:28
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivydocker/diffusers-pytorch-cpu/Dockerfile:8
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivydocker/diffusers-pytorch-cuda/Dockerfile:8
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivydocker/diffusers-onnxruntime-cuda/Dockerfile:7
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivydocker/diffusers-onnxruntime-cpu/Dockerfile:7
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivydocker/diffusers-doc-builder/Dockerfile:8
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivydocker/diffusers-pytorch-minimum-cuda/Dockerfile:11
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivydocker/diffusers-pytorch-xformers-cuda/Dockerfile:8
- AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker controlled server, or possibly an accidental resp…trivyCVE-2026-69244
- aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bombAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust …trivyCVE-2025-69223
- diffusers: Diffusers: Arbitrary code execution due to trust_remote_code guard bypassDiffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretrained flow can bypass the trust_remote_code guard because download() validates model_index.json and custom pipeline code before later loading from a cached folder t…trivyCVE-2026-45804
- Diffusers: Diffusers: Arbitrary remote code execution via `trust_remote_code` bypassDiffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omitting it, which is the default). The vulner…trivyCVE-2026-44513
- HuggingFace transformers vulnerable to remote code executionA critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attack…trivyCVE-2026-4372
- HuggingFace transformers vulnerable to remote code executionA critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attack…trivyCVE-2026-4372
- HuggingFace transformers vulnerable to remote code executionA critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attack…trivyCVE-2026-4372
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivydocker/diffusers-pytorch-cuda/Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivydocker/diffusers-pytorch-cpu/Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivydocker/diffusers-onnxruntime-cuda/Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivydocker/diffusers-onnxruntime-cpu/Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivydocker/diffusers-doc-builder/Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivydocker/diffusers-pytorch-xformers-cuda/Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivydocker/diffusers-pytorch-minimum-cuda/Dockerfile:0
- python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code settingA vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remo…trivyCVE-2026-5241
- python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code settingA vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remo…trivyCVE-2026-5241
- python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code settingA vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remo…trivyCVE-2026-5241
- python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code settingA vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remo…trivyCVE-2026-5241
- sentencepiece: Sentencepiece: Invalid memory access leading to potential arbitrary code execution via a crafted model file.Invalid memory access in Sentencepiece versions less than 0.2.1 when using a vulnerable model file, which is not created in the normal training procedure.trivyCVE-2026-1260
- starlette: Starlette DoS via Range header mergingStarlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileResponse Range parsing/merging logic. This enabl…trivyCVE-2025-62727
- starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoSStarlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, but silently ignored for application/x-www-form…trivyCVE-2026-54283
- starlette: Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on WindowsStarlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the ser…trivyCVE-2026-48818
- transformers: Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution VulnerabilityHugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit t…trivyCVE-2024-11393
- transformers: Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution VulnerabilityHugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit t…trivyCVE-2024-11393
- transformers: Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution VulnerabilityHugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit t…trivyCVE-2024-11393
- transformers: Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution VulnerabilityHugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this v…trivyCVE-2024-11392
- transformers: Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution VulnerabilityHugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this v…trivyCVE-2024-11392
- transformers: Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution VulnerabilityHugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this v…trivyCVE-2024-11392
- transformers: Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution VulnerabilityHugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vu…trivyCVE-2024-11394
- transformers: Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution VulnerabilityHugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vu…trivyCVE-2024-11394
- transformers: Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution VulnerabilityHugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vu…trivyCVE-2024-11394
- urllib3: urllib3 Streaming API improperly handles highly compressed dataurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chu…trivyCVE-2025-66471
- urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression b…trivyCVE-2026-21441
- urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headersurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.trivyCVE-2026-44431
- urllib3: urllib3: Unbounded decompression chain leads to resource exhaustionurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage a…trivyCVE-2025-66418
This report is public.