CVE-2026-100308
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process via a crafted serialized model directory.
To remediate this issue, users should upgrade to version 0.17.0 or later.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AWS | gluonts | 0 < 0.17.0 | affected |
Weaknesses
- CWE-502: CWE-502 Deserialization of untrusted data
- CWE-470: CWE-470 Use of Externally-Controlled input to select classes or code ('unsafe reflection')
References
- https://github.com/awslabs/gluonts/releases/tag/v0.17.0
- https://aws.amazon.com/security/security-bulletins/2026-119-aws/
- https://github.com/awslabs/gluonts/security/advisories/GHSA-64q6-5qv7-cwj9
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.