CVE-2026-10800
Severity CVSS v4.0:
LOW
Type:
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
Publication date:
04/06/2026
Last modified:
04/06/2026
Description
A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the component MultimodalHasher. Executing a manipulation can lead to use of weak hash. The attack requires local access. A high complexity level is associated with this attack. The exploitation is known to be difficult. This patch is called 374945747652a8d32965591c0c01a00c88b7067f. Applying a patch is advised to resolve this issue.
Impact
Base Score 4.0
2.00
Severity 4.0
LOW
Base Score 3.x
3.60
Severity 3.x
LOW
Base Score 2.0
2.40
Severity 2.0
LOW
References to Advisories, Solutions, and Tools
- https://github.com/PaddlePaddle/FastDeploy/
- https://github.com/PaddlePaddle/FastDeploy/commit/374945747652a8d32965591c0c01a00c88b7067f
- https://github.com/PaddlePaddle/FastDeploy/issues/7196
- https://github.com/PaddlePaddle/FastDeploy/pull/7185
- https://vuldb.com/cve/CVE-2026-10800
- https://vuldb.com/submit/831452
- https://vuldb.com/vuln/368249
- https://vuldb.com/vuln/368249/cti



