Skip to content
ThreatCluster

Weak Hash Vulnerabilities in MLRun and Streamlit Require Local Access

First seen 8 Oct 2026, 00:30 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 01:30 UTC
  • •CVE-2026-10766 affects MLRun versions up to 1.12.0-rc3.
  • •CVE-2026-10804 impacts Streamlit versions up to 1.53.0.
  • •Both vulnerabilities require local access and are difficult to exploit.

Two vulnerabilities, CVE-2026-10766 in MLRun and CVE-2026-10804 in Streamlit, have been identified, both utilizing weak hashing algorithms. The MLRun vulnerability affects versions up to 1.12.0-rc3 and is found in the DataFrame Hash Handler, while the Streamlit flaw impacts versions up to 1.53.0 in the Palette Handler. Both require local access and authenticated user context to exploit, with a high attack complexity. The vulnerabilities could lead to data integrity issues, cache poisoning, and potential denial-of-service conditions in applications relying on these libraries. Public exploits exist, but actual exploitation remains difficult due to the required local access and complexity. Both vulnerabilities have pending pull requests for fixes. Organizations using these tools in multi-user environments are at higher risk. Immediate upgrades to patched versions are recommended once available.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-03
CVE-2026-10766 published
A vulnerability in MLRun's DataFrame Hash Handler was disclosed, affecting versions up to 1.12.0-rc3.
Cyberattack.Ai
2026-06-03
CVE-2026-10783 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-10804 published
A vulnerability in Streamlit's Palette Handler was disclosed, affecting versions up to 1.53.0.
Cyberattack.Ai
2026-06-04
CVE-2026-10813 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-10812 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
Recent
Public exploit details disclosed
Details of the vulnerabilities were made public, but actual exploitation remains difficult due to high complexity.
Cyberattack.Ai

More articles in this cluster (2)

Following this threat?

Track CVE-2026-10766 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of MLRun and Streamlit are affected?
MLRun versions up to 1.12.0-rc3 and Streamlit versions up to 1.53.0 are affected.
How urgent is the need to patch these vulnerabilities?
While public exploit details exist, actual exploitation is difficult; however, upgrading to patched versions is recommended once available.
What are the potential impacts of these vulnerabilities?
The vulnerabilities could lead to data integrity issues, cache poisoning, and potential denial-of-service conditions in applications using these libraries.