Bounties
Partners
Community
Info
huggingface / text-generation-inference
Project repository
Large Language Model Text Generation Inference
Submit a report
FIRST INTERACTION
WITHIN
24 DAYS
REVIEW
WITHIN
25 DAYS
FIX
WITHIN
90 DAYS
SSRF via Unauthenticated /chat_tokenize Endpoint with Unrestricted Image URL Fet...
Mar 31st 2026
ryanhugh-security-fanpierlabs
•
duplicate
High
SSRF via image URL fetch with no IP/domain validation — works unauthenticated vi...
Mar 26th 2026
chrisabra-co
•
duplicate
High
Authentication bypass on /chat_tokenize — placed in info_routes instead of auth-...
Mar 24th 2026
kodareef5
•
informative
Medium
Blind SSRF via unvalidated image URL in multimodal model input processing
Mar 23rd 2026
kodareef5
•
informative
None
Authentication Bypass on `/chat_tokenize` Enables Unauthenticated SSRF
Mar 23rd 2026
seory0
•
informative
High
SSRF via Unvalidated Image URL in Chat Completion Endpoint — Cloud Metadata Exfi...
Mar 23rd 2026
nhomyk
•
informative
High
Arbitrary Code Execution via exec() of AST-Unparsed Code in Documentation Genera...
Mar 23rd 2026
nhomyk
•
informative
Critical
SSRF via Image URL Fetch in Chat Completion API — Zero SSRF Protections
Mar 19th 2026
snailsploit
•
informative
High
Path Traversal via model_id in _get_config_json in quantization.py
Mar 23rd 2026
hhhashexe
•
informative
Medium
SSRF via unvalidated image URL in idefics_image_processing.py
Mar 19th 2026
hhhashexe
•
informative
High
Unauthenticated SSRF in Text Generation Inference Idefics Image Processor
Mar 19th 2026
wheresfrank
•
informative
High
Unbounded Memory Allocation via Base64 Image Decompression Bomb in Multimodal Ch...
Mar 19th 2026
pelegs202-design
•
informative
High
Tool Call Name Constraint Bypass via Schema Property Override
Mar 23rd 2026
w0termelon
•
informative
High
Silent Prompt Manipulation via Malicious Chat Template (Supply Chain)
Mar 23rd 2026
w0termelon
•
informative
None
Server-Side Request Forgery via Unvalidated Image URL in Multimodal Chat Complet...
Mar 23rd 2026
pelegs202-design
•
informative
High
API Key Authentication Bypass on info_routes Exposes /chat_tokenize /info /metri...
Mar 23rd 2026
pelegs202-design
•
informative
Medium
SSRF via unvalidated image URL fetching in VLM chat completions endpoint
Mar 15th 2026
eistee82
•
self closed
Watermark Forgery via Hardcoded Public Hash Key
Mar 23rd 2026
w0termelon
•
informative
High
Cross-User Prompt Inference via Prefix Cache Timing Side Channel
Mar 23rd 2026
w0termelon
•
informative
Medium
Cross-LoRA Adapter Cache Poisoning in Prefix Caching
Mar 23rd 2026
w0termelon
•
informative
High
Cross-User KV Cache Access via Unauthenticated gRPC Batch Operations
Mar 23rd 2026
w0termelon
•
informative
Medium
Information Disclosure via Hardcoded Telemetry and Insecure OTLP Configuration
Mar 24th 2026
w0termelon
•
informative
Medium
Safetensors Conversion Security Control Fails to Enforce Stated Policy
Mar 23rd 2026
w0termelon
•
informative
High
SSRF via image URL fetching in VLM mode allows access to internal services and c...
Mar 19th 2026
narrator3333-hash
•
informative
High
download_weights follows base_model_name_or_path without validation, enabling su...
Mar 23rd 2026
w0termelon
•
informative
Critical
DoS via Unbounded Messages Array in Chat Completions Endpoint
Mar 19th 2026
w0termelon
•
informative
High
SSRF via HTTP Redirect Chain Bypasses URL Validation in Image Fetching
Mar 19th 2026
w0termelon
•
informative
High
KServe and Google Vertex Inference Routes Bypass API Key Authentication
Mar 23rd 2026
w0termelon
•
informative
None
API Key Authentication Uses Case-Insensitive Comparison
Mar 23rd 2026
w0termelon
•
informative
None
SSRF via Model-Generated URLs in Re-queue Validation Loop
Mar 19th 2026
w0termelon
•
informative
None
Server-Side Request Forgery (SSRF) via multimodal image URL fetching in text-gen...
Mar 16th 2026
elucidator-hky
•
self closed
Memory exhaustion via image decompression bomb in multimodal requests
Mar 19th 2026
w0termelon
•
informative
None
CPU exhaustion from inefficient token text reconstruction
Mar 19th 2026
w0termelon
•
informative
None
Memory exhaustion DoS via unbounded tokenization queue
Mar 19th 2026
w0termelon
•
informative
High
SSRF via unvalidated image URL fetching in fetch_image() allows internal netwo...
Mar 19th 2026
hbcaspa
•
informative
Medium
Remote Code Execution via trust_remote_code Parameter
Mar 23rd 2026
butlerzou-bot
•
informative
Critical
Remote Code Execution via trust_remote_code Parameter
Mar 11th 2026
butlerzou-bot
•
self closed
Remote Code Execution via trust_remote_code Parameter
Mar 11th 2026
butlerzou-bot
•
self closed
Incomplete Fix for CVE-2026-0599: Missing Timeout in Image Fetch Enables Unauthe...
Mar 8th 2026
mossharris
•
duplicate
High
API Key Authentication Bypass on Vertex AI Predict Route via AIP_PREDICT_ROUTE
Mar 23rd 2026
s3zer0
•
informative
Medium
Unsafe GGUF Model Loading Leads to Out-of-Bounds Memory Access in llama.cpp Back...
Mar 23rd 2026
directbuilds
•
informative
High
Missing Authentication on /chat_tokenize Endpoint (info_routes) Bypasses --api-k...
Mar 6th 2026
s3zer0
•
self closed
Case-Sensitive URL Prefix Check in validation.rs Allows Allowlist/Blocklist Bypa...
Mar 23rd 2026
kai-agent
•
informative
Medium
Unbounded VecDeque Queue Allows Memory Exhaustion via Request Flooding
Mar 20th 2026
kai-agent
•
informative
High
Integer Overflow in `decode_tokens` Budget Check Allows DoS
Mar 20th 2026
kai-agent
•
informative
High
TGI SSRF via Idefics Image Processor - Unrestricted URL Fetching Allows Internal...
Mar 19th 2026
avienma007
•
informative
Critical
Server-Side Request Forgery via Unauthenticated Image URL Fetching in Chat Compl...
Mar 19th 2026
avienma007
•
duplicate
Critical
Workflow_run artifact poisoning in upload_pr_documentation.yaml deploys attacker...
Mar 24th 2026
vera-platform
•
informative
Critical
Critical DoS and Blind SSRF via Unrestricted Image Fetching
Mar 19th 2026
zitoxxx
•
informative
High
Unbounded tokenization work queue enables memory-exhaustion DoS via /chat_tokeni...
Mar 20th 2026
cheonwoong-park
•
duplicate
High
Unauthenticated SSRF via Multimodal Image URL Fetching — Missing Private IP Filt...
Mar 19th 2026
hyperps
•
duplicate
Critical
Authentication Bypass on /chat_tokenize Enables Unauthenticated Server-Side Proc...
Mar 19th 2026
wernerina
•
informative
High
CUDA Graph Output Tensor Aliasing via lru_cache
Mar 23rd 2026
chawdamrunal
•
informative
High
text-generation-inference: Unbounded memory allocation via max_tokens parameter...
Mar 20th 2026
prodigysec
•
informative
High
Multiple Critical DoS Vectors: Unbounded String Expansion (OOM), Uncaught Panics...
Mar 20th 2026
alielgendy-software
•
informative
High
Image Decompression Bomb Causes DoS via Unbounded Memory Allocation in Router (I...
Mar 23rd 2026
phenggeler
•
informative
High
Unauthenticated Access to Sensitive Endpoints Bypasses Optional API Key Authenti...
Mar 23rd 2026
zeroxjacks
•
informative
Medium
Server-Side Request Forgery (SSRF) via Unvalidated Image URLs in Vision Language...
Mar 19th 2026
zeroxjacks
•
duplicate
High
Blocking HTTP Calls in Async Context Cause Thread Starvation DoS in TGI Router
Mar 20th 2026
zeroxjacks
•
informative
High
Missing HTTP Timeout Configuration Enables Indefinite Thread Blocking DoS
Mar 20th 2026
zeroxjacks
•
informative
High
Unbounded Base64 Decompression in Data URIs Causes Memory Exhaustion DoS
Mar 20th 2026
zeroxjacks
•
informative
High
Vision Token Inflation via Malicious Image Dimensions Causes Heap Exhaustion in...
Mar 20th 2026
zeroxjacks
•
informative
High
Float Parameter Validation Bypass via IEEE 754 Special Values (NaN/Infinity)
Mar 20th 2026
drrose2029
•
informative
High
DFA State Explosion Denial of Service via Unbounded Grammar Regex Compilation
Mar 23rd 2026
drrose2029
•
informative
High
router process crash via recursive $ref in JSON schema
Mar 23rd 2026
vilkasdev
•
informative
High
arbitrary code execution when loading custom CUDA kernels or operators.
Mar 23rd 2026
qian-feng
•
informative
High
SSRF via Image URL in Vision Language Model Prompts
Mar 19th 2026
theagentknownasren-gif
•
duplicate
None
HuggingFace Text-Generation-Inference fetch_image() Server-Side Request Forgery...
Mar 19th 2026
mia-718ai
•
duplicate
High
Unauthenticated SSRF in Multimodal Image Processing Enables AWS Credential Theft...
Mar 19th 2026
makeeverythingwithai-sketch
•
duplicate
Critical
Server-Side Request Forgery (SSRF) in Image Fetching
Mar 19th 2026
winters0x64
•
duplicate
Critical
Denial of Service via improper validation of max_new_tokens in Text Generation I...
Mar 23rd 2026
winters0x64
•
informative
Critical
Unauthenticated Remote Denial of Service (DoS) and Resource Exhaustion via /grad...
Mar 24th 2026
deepscott
•
informative
High
Remote Code Execution via Implicit Trust in LoRA Adapter Loading
Mar 23rd 2026
frede39-art
•
informative
Critical
Global Monkey-Patching of torch.nn.LayerNorm Enables Unsafe Deserialization Duri...
Mar 23rd 2026
hyperps
•
informative
Critical
Unbounded SSE Streaming in Python Client Causes Client-Side Denial of Service
Mar 23rd 2026
hyperps
•
informative
High
Unclaimed S3 Bucket in CI/CD Pipeline https://github.com/huggingface/text-genera...
Jan 5th 2026
gauravbhatia1211
•
informative
Critical
SSRF via Image URL Fetching Allows Access to Internal Services and Cloud Metadat...
Mar 5th 2026
jonnylitten
•
duplicate
Critical
Denial of Service via Unbounded Truncate Parameter in Neuron Backend
Mar 23rd 2026
anwarayoob
•
informative
High
SSRF in image markdown validation of Hugging Face Text Generation Inference
Mar 19th 2026
f00dat
•
duplicate
Critical
RCE risk in `update_doc.py` due to exec of AST-unparsed class
Mar 23rd 2026
7908837174
•
informative
Critical
Blind Server-Side Request Forgery (SSRF) in VLM Image URL Fetching
Mar 19th 2026
yousefabdelmohymen
•
informative
Medium
Multiple insecure deserialization vulnerabilities via chat tool parsing
Nov 13th 2025
sonw-vh
•
not applicable
Inconsistent Whitespace Formatting In Codebase
Jan 5th 2026
moonlight984
•
informative
None
Path Traversal
Jan 5th 2026
joelindra
•
informative
High
Vertex `instances` oversubscription DoS via per‑request fan‑out
Nov 13th 2025
sinon2003
•
informative
High
Regex-constrained generation DoS via heavy FSM build + per‑token filtering
Jan 5th 2026
sinon2003
•
informative
High
text-generation-inference: Unbounded external image fetch in validation leads to...
Jan 1st 2026
sinon2003
•
High
•
$750
High
•
$750
•
CVE-2026-0599
CVE-2026-0599
Arbitrary code execution leads to potential RCE via arbitrary module import (uni...
Oct 22nd 2025
joshuaprovoste
•
self closed
Arbitrary File Read / Sandbox Escape in Hugging Face Text Generation Inference
Sep 9th 2025
ko7-dev
•
duplicate
Critical
Arbitrary File Read/Sandbox Escape via model_id Path in Huggingface text-generat...
Aug 25th 2025
darkeeeandme
•
informative
High
Unauthenticated SSRF via callback_url in Hugging Face TGI /generate API CT
Jul 23rd 2025
donnyoregon
•
informative
Critical
Command Argument Injection in Model/Shard/Webserver Launch
Jul 9th 2025
joelindra
•
informative
Critical
Remote Code Execution Vulnerability in text-generation-inference via trust_remot...
Jul 9th 2025
aybanda
•
informative
Critical
Command Injection Vulnerability in bounds-from-nix.py
Jun 10th 2025
jnraris
•
informative
Critical
Remote Code Execution in CI via Malicious Model Import in HuggingFace text-gener...
Apr 17th 2025
michaelpierre
•
informative
High
The prefix cache collision problem in text-generation-inference.
Mar 25th 2025
kexinoh
•
not applicable
Code injection
Jun 10th 2024
h2oa
•
informative
Medium
•
CVE-2024-3924
CVE-2024-3924
Github action is vulnerable to arbitrary code execution
Feb 13th 2024
zmackie
•
informative
High
ReDOS in IMAGES
Jan 26th 2024
lujiefsi
•
spam
CRITICAL
$1500
HIGH
$750
MEDIUM
$125
LOW
$20