GHSA-vqwp-45wm-r9r5LowCVSS 3.6
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
🔗 CVE IDs covered (1)
📋 Description
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.
🎯 Affected products1
- pip/streamlit:< 1.53.1
🔗 References (12)
- https://nvd.nist.gov/vuln/detail/CVE-2026-10804
- https://github.com/streamlit/streamlit/issues/14622
- https://github.com/streamlit/streamlit/pull/14635
- https://github.com/streamlit/streamlit
- https://vuldb.com/cve/CVE-2026-10804
- https://vuldb.com/submit/831508
- https://vuldb.com/vuln/368253
- https://vuldb.com/vuln/368253/cti
- https://github.com/streamlit/streamlit/pull/15397
- https://github.com/streamlit/streamlit/commit/fec0f584dae9261abed16cad35b32922104bb933
- https://github.com/pypa/advisory-database/tree/main/vulns/streamlit/PYSEC-2026-212.yaml
- https://github.com/advisories/GHSA-vqwp-45wm-r9r5