Hugging Face diffusers 0.38.0 security patch release
Security Patch Release
Summary
Hide ▲
Show ▼
Hugging Face released diffusers 0.38.0 on May 1, moving security checks to dynamic-module loading and closing the identified bypass variants.
Related Happenings
RabbitMQ maintainers security patch release for CVE-2026-57219
Security Patch Release
H score29
First: 14.07.2026 16:48
Last: 14.07.2026 16:48
Sources 1
About this happening:
RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...
RabbitMQ maintainers security patch release for CVE-2026-57219
Security Patch ReleaseAbout this happening: RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...
Dify security patch release for CVE-2026-41947
Security Patch Release
H score34
First: 22.06.2026 19:13
Last: 22.06.2026 19:13
Sources 1
About this happening:
Dify shipped version 1.14.2 to fix most of the DifyTap vulnerabilities, closing cross-tenant paths that could expose AI chats, uploaded files, and internal API...
Dify security patch release for CVE-2026-41947
Security Patch ReleaseAbout this happening: Dify shipped version 1.14.2 to fix most of the DifyTap vulnerabilities, closing cross-tenant paths that could expose AI chats, uploaded files, and internal API...
LiteLLM v1.83.14-stable security fix release (multiple vulnerabilities)
Security Patch Release
H score42
First: 15.06.2026 19:39
Last: 15.06.2026 19:39
Sources 1
About this happening:
BerriAI shipped LiteLLM v1.83.14-stable to close a three-CVE chain that could let a low-privilege proxy user reach full admin and run code on the server. The u...
LiteLLM v1.83.14-stable security fix release (multiple vulnerabilities)
Security Patch ReleaseAbout this happening: BerriAI shipped LiteLLM v1.83.14-stable to close a three-CVE chain that could let a low-privilege proxy user reach full admin and run code on the server. The u...
Major Linux distributions CIFSwitch fixes
Security Patch Release
H score27
First: 01.06.2026 14:19
Last: 01.06.2026 14:19
Sources 1
About this happening:
Major Linux distributions rolled out fixes for the CIFSwitch security defect, reducing exposure to a root-privilege escalation path in the Linux kernel CIFS subsyste...
Major Linux distributions CIFSwitch fixes
Security Patch ReleaseAbout this happening: Major Linux distributions rolled out fixes for the CIFSwitch security defect, reducing exposure to a root-privilege escalation path in the Linux kernel CIFS subsyste...
Timeline
-
27.07.2026 03:00 1 articles · 1d ago
Zafran Security publishes diffusers flaw analysis
Technical Analysis UpdateZafran Security published its July 27 analysis of three high-severity diffusers flaws, including CVE-2026-44827, CVE-2026-45804, and CVE-2026-44513, and described how crafted model repositories could bypass trust_remote_code during affected loading flows.
Show sources
- Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard — www.infosecurity-magazine.com — 28.07.2026 18:15
-
01.05.2026 03:00 2 articles · 2mo ago
Hugging Face releases diffusers 0.38.0 to close the bypass variants
Mitigation Patch UpdateHugging Face released diffusers 0.38.0 on May 1 and moved the security checks to the dynamic-module loading step, closing the identified bypass variants in affected loading flows.
Show sources
- Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard — www.infosecurity-magazine.com — 28.07.2026 18:15
- Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard — www.infosecurity-magazine.com — 28.07.2026 18:15
-
19.03.2026 02:00 1 articles · 4mo ago
Zafran reports diffusers bypass flaws to Hugging Face
Initial DisclosureZafran Security reported two Hugging Face diffusers flaws on March 19 that could bypass trust_remote_code and let crafted model repositories execute arbitrary code during model loading.
Show sources
- Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard — www.infosecurity-magazine.com — 28.07.2026 18:15