CVE-2026-0599 describes a critical vulnerability in huggingface/text-generation-inference version 3.3.6, allowing unauthenticated remote attackers to trigger unbounded external image fetching during input validation in VLM mode. This flaw, rated High severity (CVSS 7.5), can lead to resource exhaustion, including network saturation, memory inflation, and CPU overutilization, potentially crashing the host machine due to a lack of memory limits in default deployments. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability. The issue is resolved in version 3.3.7.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Huggingface | Huggingface/Text-Generation-Inference | >= unspecified, < 3.3.7CNA affected |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.