CVE-2026-15605CWE-327CWE-328

wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.download weak hash

Low · published July 13, 2026

CVSS v4.0
2.3
EPSS
0%
Percentile
14.1
In the wild
Unconfirmed
What it is

A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the component Artifact Integrity Validation. The manipulation leads to use of weak hash. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The pull request to fix this issue awaits acceptance.

The record
Technical detail
CVSS v4.0
2.3 · LOW
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X
EPSS
0.00233 · 14.1th percentile
Weaknesses
CWE-327 · Use of a Broken or Risky Cryptographic Algorithm; CWE-328 · Use of Weak Hash
Published
2026-07-13T22:45Z
EPSS history
Timeline
  • 13 JUL 22:45Z
    wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.download weak hash
    cvelistv5