Skip to content

Security vulnerabilities in MLeap serving stack - requesting private reporting channel #897

@addcontent

Description

@addcontent

Hello maintainers,

I've identified multiple security vulnerabilities in the MLeap serving modules (mleap-spring-boot, mleap-executor, mleap-grpc-server) affecting the current release (v0.24.0). These include issues that allow unauthenticated remote callers to crash the service and influence server-side network behavior.

I'd prefer to share the full details privately before any public disclosure. Could you point me to a secure reporting channel; email, GitHub private vulnerability reporting, or similar?

I've also sent details to combust@combust.ml in parallel.

Thanks,
addcontent

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions