Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. text-generation
  4. ›
  5. CVE-2026-0599

CVE-2026-0599: Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumption

February 2, 2026

A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to exploit unbounded external image fetching during input validation in VLM mode. The issue arises when the router scans inputs for Markdown image links and performs a blocking HTTP GET request, reading the entire response body into memory and cloning it before decoding. This behavior can lead to resource exhaustion, including network bandwidth saturation, memory inflation, and CPU overutilization. The vulnerability is triggered even if the request is later rejected for exceeding token limits. The default deployment configuration, which lacks memory usage limits and authentication, exacerbates the impact, potentially crashing the host machine. The issue is resolved in version 3.3.7.

References

  • github.com/advisories/GHSA-j7x9-7j54-2v3h
  • github.com/huggingface/text-generation-inference
  • github.com/huggingface/text-generation-inference/commit/24ee40d143d8d046039f12f76940a85886cbe152
  • huntr.com/bounties/1d3f2085-666c-4441-b265-22f6f7d8d9cd
  • nvd.nist.gov/vuln/detail/CVE-2026-0599

Code Behaviors & Features

Detect and mitigate CVE-2026-0599 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 3.3.7

Fixed versions

  • 3.3.7

Solution

Upgrade to version 3.3.7 or above.

Impact 7.5 HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-400: Uncontrolled Resource Consumption

Source file

pypi/text-generation/CVE-2026-0599.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 04 Feb 2026 00:35:52 +0000.