PT-2026-60247 · Git+1 · Gpustack

·

CVE-2026-58658

·

Published

2026-07-15

·

Updated

2026-07-15

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GPUStack versions prior to 2.2.1
Description An unauthenticated information disclosure issue allows attackers to access sensitive inference logs and modify worker configuration. This is achieved by exploiting the unprotected '/serveLogs' and '/debug' endpoints on the worker port. Attackers can enumerate model instance IDs to stream serving logs containing prompts and completions, change log levels, and read memory profiling data without authentication.
Recommendations Update to the version containing commit 4e20551. Restrict access to the '/serveLogs' and '/debug' endpoints to minimize the risk of exploitation.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58658

Affected Products

Gpustack