CVE-2026-87083
Dashboard / Vulnerabilities / CVE-2026-87083
CVE-2026-87083
Summary: tile-ai tilelang Kernel Cache kernel_cache.py KernelCache._load_kernel_from_disk deserialization
Details: A weakness has been identified in tile-ai tilelang up to 0.1.14. This impacts the function KernelCache._load_kernel_from_disk of the file tilelang/cache/kernel_cache.py of the component Kernel Cache. Executing a manipulation can lead to deserialization. The attack may be performed from remote. This patch is called 11ec2397fe942e8b422d026af4a03d6e0a55ae6c. Applying a patch is advised to resolve this issue. Based on the release information, the fix has not been included in any official release yet.
References: https://github.com/tile-ai/tilelang/, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87083.json, https://nvd.nist.gov/vuln/detail/CVE-2026-87083, https://vuldb.com/cve/CVE-2026-87083, https://vuldb.com/submit/911126, https://vuldb.com/vuln/400289, https://github.com/tile-ai/tilelang/issues/2817, https://vuldb.com/vuln/400289/cti, https://github.com/tile-ai/tilelang/commit/11ec2397fe942e8b422d026af4a03d6e0a55ae6c, https://github.com/tile-ai/tilelang/pull/3143
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
