DJL (Deep Java Library) is a modest machine-learning framework that provides abstraction layers across deep-learning engines, with a narrow product scope centered on the core library itself. The observed vulnerability pattern reflects path-traversal weaknesses, which are characteristic of file-handling and resource-loading code paths that bridge user-supplied inputs to filesystem operations. Current CVE counts, severity, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Djl over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2914HIGH A TarSlip vulnerability exists in the deepjavalibrary/djl, affecting version 0.26.0 and fixed in version 0.27.0. This vulnerability allows an attacker to manipulate file paths with | Jun 6, 2024 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Djl.
Media articles that mention a CVE ID that affects a product developed by Djl — matched by CVE ID, not by vendor name.