{"id":"CVE-2026-10804","aliases":["GHSA-vqwp-45wm-r9r5","PYSEC-2026-212"],"url":"https://o3.security/vulnerability/CVE-2026-10804","summary":"Streamlit Palette hashing.py weak hash","details":"A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.","published":"2026-06-04T12:00:14.916Z","modified":"2026-08-12T03:51:13.039764461Z","cvss":null,"epss":{"score":0.00083,"percentile":0.00288,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"streamlit","fixedVersion":"1.53.1"}],"fix":{"url":"https://github.com/streamlit/streamlit/pull/14635","label":"streamlit/streamlit#14635"},"references":[{"type":"WEB","url":"https://github.com/streamlit/streamlit/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10804.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10804"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-10804"},{"type":"ADVISORY","url":"https://vuldb.com/submit/831508"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/368253"},{"type":"REPORT","url":"https://github.com/streamlit/streamlit/issues/14622"},{"type":"REPORT","url":"https://vuldb.com/vuln/368253/cti"},{"type":"FIX","url":"https://github.com/streamlit/streamlit/pull/14635"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:13.039764461Z"}}