Security: JustVugg/colibri
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
inkling engine `load_scalar()`: stack buffer overflow via crafted safetensors tensor — attacker controls RSPGHSA-pmq2-6f2p-hjvf published
Aug 5, 2026 by JustVuggHigh -
inkling engine `load_cfg()`: out-of-bounds read on `layer_types` array via crafted config.jsonGHSA-c84r-hmpc-qg8h published
Aug 5, 2026 by JustVuggHigh -
inkling SERVE protocol: negative `max_tok` bypasses context-length check, causing KV-cache heap out-of-bounds writeGHSA-2h73-p2rc-4796 published
Aug 5, 2026 by JustVuggHigh -
NaN router logits leave MoE top-k selection at best=-1, causing negative-index heap OOB read/write and negative-offset preadGHSA-5xpg-vw35-2687 published
Aug 5, 2026 by JustVuggHigh -
Unbounded thread creation & slowloris drip bypass of per-read timeout leads to memory exhaustion DoSGHSA-25w8-8c74-g9c8 published
Aug 5, 2026 by JustVuggModerate -
Unauthenticated access to `/profile` endpoint leaks per-turn inference telemetryGHSA-rfqv-4g4x-j4vr published
Aug 5, 2026 by JustVuggModerate -
Heap out-of-bounds write in c/st.h safetensors loader: unvalidated tensor metadata overflows heap buffer on model loadGHSA-4gw4-j89j-4c8r published
Aug 5, 2026 by JustVuggHigh -
Untrusted model files cause out-of-bounds writes / heap corruption in the native loader (tok.h/st.h/json.h)GHSA-wc4x-3786-cxh7 published
Aug 5, 2026 by JustVuggHigh
Learn more about advisories related to JustVugg/colibri in the GitHub Advisory Database