Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-103270

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Sep 30, 2026
Vendor unknown

Description

LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group to disrupt inference operations and wedge workers on deployments started with --enable_rl.

References