CVE-2026-26220 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disaggregation mode. The PD master node e…
Critical CVSS: 9.3

CVE-2026-26220

LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disaggregation mode. The PD master node exposes WebSocket endpoints that receive binary frames and pass the data directly to pickle.loads() without authentication or validation. A remote attacker who can reach the PD master can send a crafted payload to achieve arbitrary code execution.
Vendor
-
Product
-
CWE
CWE-502
Yayın Tarihi
2026-02-17 03:16:01
Güncelleme
2026-02-18 17:52:22
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar