Unrated severityNVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026
GPUStack Unauthenticated Information Disclosure via Worker Endpoints
CVE-2026-58658
Description
GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to access sensitive inference logs and modify worker configuration by exploiting unprotected /serveLogs and /debug endpoints on the worker port. Attackers can enumerate model instance IDs to stream serving logs containing prompts and completions, change log levels, and read memory profiling data without any authentication.
Affected products
1Patches
Vulnerability mechanics
References
3- github.com/gpustack/gpustack/commit/4e20551b5aaf76f93a8769d32b7fef999e22a4d3mitrepatch
- github.com/gpustack/gpustack/issues/5836mitretechnical-descriptionexploitissue-tracking
- www.vulncheck.com/advisories/gpustack-unauthenticated-information-disclosure-via-worker-endpointsmitrethird-party-advisory
News mentions
0No linked articles in our index yet.