Find notable cyber news and cases, enriched with sources, timelines, and signals.

Hugging Face diffusers 0.38.0 security patch release

Security Patch Release
First reported
Last updated
Happening score
H score 25
2 unique sources, 2 articles

Summary

Hide ▲

Hugging Face Diffusers vulnerabilities tied to trust_remote_code bypasses were disclosed by Zafran Security and later patched in diffusers 0.38.0. The flaw set, named FaceHugger, includes CVE-2026-44827, CVE-2026-45804, and CVE-2026-44513, and can let crafted model repositories trigger arbitrary code execution during model loading. The release moved checks to the dynamic-module loading step and closes the identified bypass variants. Systems that call DiffusionPipeline.from_pretrained with custom pipelines are impacted, especially in AI pipelines, CI/CD systems, and container images.

Related Happenings

Adobe security patch release for CVE-2026-48395

Security Patch Release
H score39 First: 01.08.2026 10:12 Last: 01.08.2026 10:12 Sources 1

About this happening: Adobe shipped a security update for Adobe Bridge on 2026-08-01 that closes eight critical-rated flaws with risk of privilege escalation and arbitrary code execut...

Ruflo maintainer Reuven Cohen security patch release for CVE-2026-59726

Security Patch Release
H score45 First: 29.07.2026 18:39 Last: 29.07.2026 18:39 Sources 1

About this happening: Ruflo pushed a fix for CVE-2026-59726, closing a maximum-severity unauthenticated RCE issue in the project's default MCP bridge. The patch landed within 24 hours...

RabbitMQ maintainers security patch release for CVE-2026-57219

Security Patch Release
H score29 First: 14.07.2026 16:48 Last: 14.07.2026 16:48 Sources 1

About this happening: RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...

Dify security patch release for CVE-2026-41947

Security Patch Release
H score34 First: 22.06.2026 19:13 Last: 22.06.2026 19:13 Sources 1

About this happening: Dify shipped version 1.14.2 to fix most of the DifyTap vulnerabilities, closing cross-tenant paths that could expose AI chats, uploaded files, and internal API...

LiteLLM v1.83.14-stable security fix release (multiple vulnerabilities)

Security Patch Release
H score42 First: 15.06.2026 19:39 Last: 15.06.2026 19:39 Sources 1

About this happening: BerriAI shipped LiteLLM v1.83.14-stable to close a three-CVE chain that could let a low-privilege proxy user reach full admin and run code on the server. The u...

Timeline

  1. 27.07.2026 03:00 1 articles · 11d ago

    Zafran Security publishes diffusers flaw analysis

    Technical Analysis Update

    Zafran Security published its July 27 analysis of three high-severity diffusers flaws, including CVE-2026-44827, CVE-2026-45804, and CVE-2026-44513, and described how crafted model repositories could bypass trust_remote_code during affected loading flows.

    Show sources
  2. 01.05.2026 03:00 3 articles · 3mo ago

    Hugging Face releases diffusers 0.38.0 to close the bypass variants

    Mitigation Patch Update

    Hugging Face released diffusers 0.38.0 on May 1 and moved the security checks to the dynamic-module loading step, closing the identified bypass variants in affected loading flows.

    Show sources
  3. 19.03.2026 02:00 1 articles · 4mo ago

    Zafran reports diffusers bypass flaws to Hugging Face

    Initial Disclosure

    Zafran Security reported two Hugging Face diffusers flaws on March 19 that could bypass trust_remote_code and let crafted model repositories execute arbitrary code during model loading.

    Show sources