Junglewise Threat Intelligence

CVE-2026-100308: Amazon GluonTS unsafe deserialization in model loading

CVE-2026-100308 · Severity: high · CVSS 7.8 · Published 2026-09-29

Technologies: Amazon AWS. Vendors: Amazon.

Executive brief

Amazon GluonTS is a machine learning library used to build deep learning models for time series forecasting. A flaw in how it deserializes model files allows attackers to execute arbitrary commands on systems that load untrusted models, potentially giving attackers complete control of the server or application running the library.

Technical details

The vulnerability exists in the Predictor.deserialize() and RepresentablePredictor.deserialize() methods, which fail to safely validate untrusted serialized model artifacts before deserialization, allowing arbitrary code execution through specially crafted model directories. An attacker can exploit this by providing a malicious model file that executes OS commands with the privileges of the process loading the model. The fix in version 0.17.0 restricts deserialization to known-serializable types and resolves unsafe torch.load usage.

Affected products

  • Amazon GluonTS before 0.17.0

Timeline

  • 2026-09-29: disclosed

References

Related threats