CVE-2026-15605

Severity CVSS v4.0:
LOW
Type:
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Publication date:
13/07/2026
Last modified:
14/07/2026

Description

A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the component Artifact Integrity Validation. The manipulation leads to use of weak hash. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The pull request to fix this issue awaits acceptance.