Deserialization Vulnerability in Amazon GluonTS Product by AWS
CVE-2026-100308
8.4HIGH
What is CVE-2026-100308?
A deserialization vulnerability exists in the model loading component of Amazon GluonTS prior to version 0.17.0. This flaw permits context-dependent attackers to execute arbitrary operating system commands by leveraging a crafted serialized model directory. To safeguard against potential exploitation, it is essential for users to upgrade to version 0.17.0 or later.
Affected Version(s)
gluonts 0 < 0.17.0
