Vulnerability Description
A vulnerability was detected in zilliztech GPTCache up to 0.1.44. Affected by this issue is the function BufferedReader.peek of the file gptcache/processor/pre.py of the component Cache Key Handler. Performing a manipulation of the argument input_data["image"] results in use of weak hash. The attack must be initiated from a local position. The attack is considered to have high complexity. The exploitation is known to be difficult. The exploit is now public and may be used. The pull request to fix this issue awaits acceptance.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/zilliztech/GPTCache/
- https://github.com/zilliztech/GPTCache/issues/684
- https://github.com/zilliztech/GPTCache/pull/678
- https://vuldb.com/cve/CVE-2026-10812
- https://vuldb.com/submit/831636
- https://vuldb.com/vuln/368260
- https://vuldb.com/vuln/368260/cti
FAQ
What is CVE-2026-10812?
CVE-2026-10812 is a vulnerability with a CVSS score of 3.6 (LOW). A vulnerability was detected in zilliztech GPTCache up to 0.1.44. Affected by this issue is the function BufferedReader.peek of the file gptcache/processor/pre.py of the component Cache Key Handler. P...
How severe is CVE-2026-10812?
CVE-2026-10812 has been rated LOW with a CVSS base score of 3.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-10812?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.