Junglewise Threat Intelligence

CVE-2026-58658: GPUStack unauthenticated information disclosure in worker endpoints

CVE-2026-58658 · Severity: high · CVSS 8.2 · Published 2026-07-15

Executive brief

GPUStack, a platform for managing GPU clusters for AI model serving, contains a security flaw where worker nodes expose sensitive data without requiring a password. An attacker can remotely access private AI chat logs, including user prompts and model responses, and modify system settings like logging levels. This could lead to the exposure of proprietary information or sensitive customer data processed by the AI models.

Technical details

GPUStack worker nodes fail to enforce authentication on the /serveLogs and /debug endpoints (typically on port 10150). The root cause is a missing authentication dependency in the FastAPI router configuration within gpustack/worker/worker.py. An unauthenticated remote attacker can enumerate model instance IDs to stream serving logs containing plaintext prompts and completions. Additionally, attackers can read memory profiling data and modify the worker's log level via PUT requests to the /debug/log_level endpoint. The vulnerability is addressed in commit 4e20551 by applying the worker_request_auth dependency to the affected routers.

Affected products

  • GPUStack GPUStack through 2.2.1

Timeline

  • 2026-06-09: disclosed: Vulnerability reported to vendor via email
  • 2026-07-10: other: Public issue tracker entry created
  • 2026-07-15: advisory: NVD and VulnCheck advisories published
  • 2026-07-15: patched: Fix committed in version 2.2.2 (commit 4e20551)

References