Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.
cvss
0.0
high
severity band, no base score published
epss
not scored
chance of exploitation in 30 days
xyz score
0.0
low
CyberXYZ composite out of 10
fig. 01 — GHSA-c8m9-mh38-97p9, the advisory selected below
// 1 advisories
GHSA-c8m9-mh38-97p9
HIGH
An XML eXternal Entity (XXE) Injection was discovered in pmml-model before version 1.4.3. A remote attacker can exploit this vulnerability by sending a request to submit malicious External Entity references within the embedded XML metadata to the target system.
Checked 2026-10-04 at 02:27 UTC. The most recent advisory here was published 2021-02-24. Updated continuously from NVD, GHSA, OSV and CNA feeds.