CVE-2026-10800: Use of Weak Hash in PaddlePaddle FastDeploy
A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the component MultimodalHasher. Executing a manipulation can lead to use of weak hash. The attack requires local access. A high complexity level is associated with this attack. The exploitation is known to be difficult. This patch is called 374945747652a8d32965591c0c01a00c88b7067f. Applying a patch is advised to resolve this issue.
AI Analysis
Technical Summary
CVE-2026-10800 describes a vulnerability in PaddlePaddle FastDeploy versions 2.4.0 and 2.4.1 where the hash_features function in fastdeploy/multimodal/hasher.py uses a weak hash algorithm. Exploitation requires local access and is complex, with no known exploits in the wild. A patch has been created to address this issue, though no official remediation level or vendor advisory is provided in the data. The CVSS 4.0 score is 2.0, reflecting low severity.
Potential Impact
The use of a weak hash function could potentially undermine data integrity or security features relying on this hash. However, the attack complexity is high, requiring local access, and exploitation is difficult. There are no known exploits in the wild, and the overall severity is low.
Mitigation Recommendations
A patch identified by commit 374945747652a8d32965591c0c01a00c88b7067f is available and applying it is advised to resolve the issue. Since no official vendor advisory or remediation level is provided, users should monitor PaddlePaddle's official channels for the patch release and apply it promptly once available.
CVE-2026-10800: Use of Weak Hash in PaddlePaddle FastDeploy
Description
A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the component MultimodalHasher. Executing a manipulation can lead to use of weak hash. The attack requires local access. A high complexity level is associated with this attack. The exploitation is known to be difficult. This patch is called 374945747652a8d32965591c0c01a00c88b7067f. Applying a patch is advised to resolve this issue.
CVSS v4.0
Score 2.0low
Affected software
pkg:github/paddlepaddle/FastDeployRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-10800 describes a vulnerability in PaddlePaddle FastDeploy versions 2.4.0 and 2.4.1 where the hash_features function in fastdeploy/multimodal/hasher.py uses a weak hash algorithm. Exploitation requires local access and is complex, with no known exploits in the wild. A patch has been created to address this issue, though no official remediation level or vendor advisory is provided in the data. The CVSS 4.0 score is 2.0, reflecting low severity.
Potential Impact
The use of a weak hash function could potentially undermine data integrity or security features relying on this hash. However, the attack complexity is high, requiring local access, and exploitation is difficult. There are no known exploits in the wild, and the overall severity is low.
Mitigation Recommendations
A patch identified by commit 374945747652a8d32965591c0c01a00c88b7067f is available and applying it is advised to resolve the issue. Since no official vendor advisory or remediation level is provided, users should monitor PaddlePaddle's official channels for the patch release and apply it promptly once available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-06-04T04:57:09.234Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a214d96e29bf47b5092323a
Added to database: 06/04/2026, 10:04:06 UTC
Last enriched: 06/11/2026, 13:09:34 UTC
Last updated: 07/31/2026, 19:22:57 UTC
Views: 57
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.