CWE-704
CWE-704 · 3 records · 3 with a public proof-of-concept
Records the NVD classes under CWE-704, highest CVSS first.
- MEDIUM 6.5CVE-2026-105754public PoC
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the /inference/v1/generate endpoint in the disaggregated scale-out path accepts caller-supplied tensors in the features.kwargs_data field, cache identifiers in the features.mm_…
vllm
- MEDIUM 5.3CVE-2026-104420public PoC
Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step wrongly downcasts RouterError to VerifyBlockError and discards the score, s…
- UNSCOREDCVE-2026-104634public PoC
Incorrect Type Conversion or Cast vulnerability in BeamMCP.Server in ScriptKittyOS beam_mcp allows an MCP client's JSON true, false and null tool arguments to reach the host's dispatch function as the strings "true", "false" and "nil". After BeamMCP.Schema.val…