CVE-2026-75090Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. Affected by this issue is the function convert_gguf_to_hf_tokenizer of the file mistralrs-core/src/gguf/gguf_tokenizer.rs of the component GGUF Tokenizer. The manipulation of the argument eos_token_id/bos_token_id/unknown_token_id results in out-of-bounds read. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 0.8.23 can resolve this issue. The patch is identified as cd5297e2ea5cb27c790bdcf2f3c2f1064a81d55e. Upgrading the affected component is recommended.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-18: 3Patch / Workaround · 2026-08-18: 1Technical Details · 2026-08-18: 308-18
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets5 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-75090 A vulnerability was detected in EricLBuehler https://Mistral.rs up to 0.8.22. Affected by this issue is the function convert_gguf_to_hf_tokenizer of the file mistralrs-core/s… https://www.cve.org/CVERecord?id=CVE-2026-75090

    Post summary

    CVE-2026-75090 is reported for Mistral.rs versions up to 0.8.22, impacting the convert_gguf_to_hf_tokenizer function; no exploitation or patch information is provided.

    00000651
    58.0K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    CyberSec Daily ✓ · 🧠 AI Vulnerability · August 18, 2026 🎯 New vulnerability published in the http://Mistral.rs AI inference stack A new CVE published into vulnerability feeds on August 18 affects http://Mistral.rs, an open-source framework used for running AI models. Tracked as CVE-2026-75090, the issue affects http://Mistral.rs through version 0.8.22 and involves unsafe handling inside its GGUF tokenizer processing. Vulnerability databases indicate that affected systems should upgrade to version 0.8.23, which contains the fix. The disclosure is another example of the security surface expanding around AI runtimes, model loaders and inference infrastructure, not only the models themselves. 🔗 Source: CVE / Tenable / VulDB #MistralRS #AISecurity #CVE202675090 #LLM #MLOps #CyberSecurity #Vulnerability

    Post summary

    The post announces CVE-2026-75090 affecting Mistral.rs through 0.8.22, describing unsafe tokenization handling and recommending an upgrade to 0.8.23 for a fix.

    0000043
    75 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-75090 Out-of-Bounds Read in EricLBuehler https://Mistral.rs GGUF Tokenizer https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-75090 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    CVE-2026-75090 is an out‑of‑bounds read vulnerability in the GGUF Tokenizer, with technical details disclosed but no PoC, exploit, or patch referenced.

    00000120
    4.1K followersView on X

Explore more