Deserialization Vulnerability in tile-ai's tilelang Kernel Cache Component
CVE-2026-87083

5.1MEDIUM

Key Information:

Vendor

Tile-ai

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-87083?

A vulnerability exists in tile-ai's tilelang up to version 0.1.14, specifically in the KernelCache component. The flaw in the function KernelCache._load_kernel_from_disk located in tilelang/cache/kernel_cache.py allows for potential remote deserialization attacks. Intruders may exploit this issue to manipulate the system remotely. While a patch (11ec2397fe942e8b422d026af4a03d6e0a55ae6c) has been developed to address this concern, it has yet to be included in an official release. It is recommended to apply the patch to safeguard against possible exploitation.

Affected Version(s)

tilelang 0.1.0

tilelang 0.1.1

tilelang 0.1.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Customeres (VulDB User)
VulDB CNA Team
.