CVE-2026-100308

Summary

Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process via a crafted serialized model directory.

To remediate this issue, users should upgrade to version 0.17.0 or later.

Affected Software

VendorProductVersion RangeStatus
AWSgluonts0 < 0.17.0affected

Weaknesses

  • CWE-502: CWE-502 Deserialization of untrusted data
  • CWE-470: CWE-470 Use of Externally-Controlled input to select classes or code ('unsafe reflection')

References