VYPR

Lightgbm

by Lightgbm Org

CVEs (1)

  • CVE-2026-92786HigSep 16, 2026
    risk 0.51cvss 7.8epss

    LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction. Attackers can craft malicious model files with invalid node references that trigger out-of-bounds writes at…