CVE-2026-31222
- EPSS 0.39%
- Veröffentlicht 12.05.2026 00:00:00
- Zuletzt bearbeitet 15.05.2026 19:16:57
The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() method of the Trainer class. The method loads model checkpoint files using torch.load() without enabling the security-restrictive weig...
CVE-2026-31223
- EPSS 0.39%
- Veröffentlicht 12.05.2026 00:00:00
- Zuletzt bearbeitet 15.05.2026 19:16:57
The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler.load() method of the BaseLabeler class. The method loads serialized labeler models using the unsafe pickle.load() function on use...
CVE-2026-31224
- EPSS 0.39%
- Veröffentlicht 12.05.2026 00:00:00
- Zuletzt bearbeitet 13.05.2026 15:44:54
The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier.load() method of the MultitaskClassifier class. The method loads model weight files using torch.load() without enabling the secur...