Low severity3.6NVD Advisory· Published Jun 4, 2026· Updated Jul 22, 2026
CVE-2026-10804
CVE-2026-10804
Description
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
streamlitPyPI | < 1.53.1 | 1.53.1 |
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=1.53.0
Patches
Vulnerability mechanics
References
11- github.com/streamlit/streamlit/issues/14622nvdIssue TrackingMitigationPatchWEB
- github.com/streamlit/streamlit/pull/14635nvdIssue TrackingPatchWEB
- github.com/advisories/GHSA-vqwp-45wm-r9r5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-10804ghsaADVISORY
- vuldb.com/cve/CVE-2026-10804nvdThird Party AdvisoryVDB EntryWEB
- vuldb.com/submit/831508nvdThird Party AdvisoryVDB EntryWEB
- vuldb.com/vuln/368253nvdThird Party AdvisoryVDB EntryWEB
- github.com/pypa/advisory-database/tree/main/vulns/streamlit/PYSEC-2026-212.yamlghsaWEB
- github.com/streamlit/streamlit/commit/fec0f584dae9261abed16cad35b32922104bb933ghsaWEB
- github.com/streamlit/streamlit/pull/15397ghsaWEB
- vuldb.com/vuln/368253/ctinvdPermissions RequiredVDB EntryWEB
News mentions
0No linked articles in our index yet.