<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:52:19 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-44484 — Compromise of PyTorch Lightning PyPi Package Versions</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-44484</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Lightning-AI pytorch-lightning, Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI)&lt;/p&gt;
&lt;p&gt;PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Lightning-AI pytorch-lightning, Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI)&lt;/p&gt;
&lt;p&gt;PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-44484</guid>
    </item>
    <item>
      <title>GHSA-w37p-236h-pfx3 — Compromise of PyTorch Lightning PyPi Package Versions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w37p-236h-pfx3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pytorch-lightning&lt;/p&gt;
&lt;p&gt;# Security Advisory: Compromise of PyTorch Lightning PyPI Package Versions&lt;/p&gt;
&lt;p&gt;**Published:** 2026-04-30  
**Last Updated:** 2026-05-12&lt;/p&gt;
&lt;p&gt;**Github Advisory:** [CVE-2026-44484](https://github.com/advisories/GHSA-w37p-236h-pfx3)&lt;/p&gt;
&lt;p&gt;We have identified a security incident affecting certain versions of one of our PyPI packages.&lt;/p&gt;
&lt;p&gt;## What happened&lt;/p&gt;
&lt;p&gt;We have determined that one or more released versions of this package have been compromised and include malicious code.&lt;/p&gt;
&lt;p&gt;Our current investigation indicates that the affected versions have introduced functionality consistent with a credential harvesting mechanism. We are still actively analysing the scope and behaviour of the code.&lt;/p&gt;
&lt;p&gt;At this stage, the root cause of the compromise is still under investigation.&lt;/p&gt;
&lt;p&gt;## What versions are affected&lt;/p&gt;
&lt;p&gt;We are currently working to confirm the exact set of impacted versions.&lt;/p&gt;
&lt;p&gt;We have determined the following versions as affected and ask that you delete them from your systems:&lt;/p&gt;
&lt;p&gt;- `2.6.2`
- `2.6.3`&lt;/p&gt;
&lt;p&gt;We will update this advisory if the versions impacted by this vulnerability change.&lt;/p&gt;
&lt;p&gt;## What you should do immediately&lt;/p&gt;
&lt;p&gt;If you have installed or are running any potentially affected versions:&lt;/p&gt;
&lt;p&gt;- Assume the environment may be compromised  
- Immediately rotate all credentials and secrets that may have been exposed, including:  
  - API keys  
  - Access tokens  
  - SSH keys  
  - Service account credentials  
- Rebuild affected systems from a known clean state  
- Pin PyTorch Lightning to version `2.6.1`  
- Revi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pytorch-lightning&lt;/p&gt;
&lt;p&gt;# Security Advisory: Compromise of PyTorch Lightning PyPI Package Versions&lt;/p&gt;
&lt;p&gt;**Published:** 2026-04-30  
**Last Updated:** 2026-05-12&lt;/p&gt;
&lt;p&gt;**Github Advisory:** [CVE-2026-44484](https://github.com/advisories/GHSA-w37p-236h-pfx3)&lt;/p&gt;
&lt;p&gt;We have identified a security incident affecting certain versions of one of our PyPI packages.&lt;/p&gt;
&lt;p&gt;## What happened&lt;/p&gt;
&lt;p&gt;We have determined that one or more released versions of this package have been compromised and include malicious code.&lt;/p&gt;
&lt;p&gt;Our current investigation indicates that the affected versions have introduced functionality consistent with a credential harvesting mechanism. We are still actively analysing the scope and behaviour of the code.&lt;/p&gt;
&lt;p&gt;At this stage, the root cause of the compromise is still under investigation.&lt;/p&gt;
&lt;p&gt;## What versions are affected&lt;/p&gt;
&lt;p&gt;We are currently working to confirm the exact set of impacted versions.&lt;/p&gt;
&lt;p&gt;We have determined the following versions as affected and ask that you delete them from your systems:&lt;/p&gt;
&lt;p&gt;- `2.6.2`
- `2.6.3`&lt;/p&gt;
&lt;p&gt;We will update this advisory if the versions impacted by this vulnerability change.&lt;/p&gt;
&lt;p&gt;## What you should do immediately&lt;/p&gt;
&lt;p&gt;If you have installed or are running any potentially affected versions:&lt;/p&gt;
&lt;p&gt;- Assume the environment may be compromised  
- Immediately rotate all credentials and secrets that may have been exposed, including:  
  - API keys  
  - Access tokens  
  - SSH keys  
  - Service account credentials  
- Rebuild affected systems from a known clean state  
- Pin PyTorch Lightning to version `2.6.1`  
- Revi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w37p-236h-pfx3</guid>
    </item>
  </channel>
</rss>
