Products: 1
    Vulnerabilities: 3
    Known Exploited: 0
    2
    Critical Level Threats
    1
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-31234

    Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server component. The KVStore server, used for distributed task coordination, lacks authentication and authorization controls, allowing any remote attacker to write arbitrary data via HTTP PUT requests. When a Horovod worker reads data from the KVStore (via HTTP GET), it deserializes the data using cloudpickle.loads() without verifying its source or integrity. An attacker can exploit this by sending a malicious pickle payload to the server before the legitimate data is written, causing the victim worker to deserialize and execute arbitrary code, leading to remote code execution.

    Last Modified: May 14, 2026
    Published: May 12, 2026

    CVE-2024-10190

    Unauthenticated Remote Code Execution in ElasticRendezvousHandler in horovod/horovod

    Last Modified: Dec 11, 2025
    Published: Mar 20, 2025

    CVE-2022-0315

    Insecure Temporary File in horovod/horovod

    Last Modified: Nov 21, 2024
    Published: Mar 24, 2022
    Items Per Page
    Horovod Vulnerabilities & Security CVEs | CVE-DB