CVE-2026-73219CWE-1288

CVE-2026-73219

published August 11, 2026

CVSS
5.3
EPSS
0%
Percentile
27.0
In the wild
Unconfirmed
What it is

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with write access to a CVAT job can submit a batch automatic annotation request to RequestViewSet.create with inconsistent task and job IDs, and because the task ID determines the single active request slot, block automatic annotation for another task whose ID is known. This issue is fixed in version 2.72.0.

The record
Technical detail
CVSS
5.3 · NONE
CVSS v4.0
Not supplied
EPSS
0.00341 · 27.0th percentile
Weakness
CWE-1288 · Improper Validation of Consistency within Input
Published
2026-08-11T22:18Z
References (4)
EPSS history
Timeline
  • 11 AUG 17:50Z
    CVAT: Denial of service with regards to automatic annotation
    cvelistv5