CVE 2 LOW

Streamlit Palette hashing.py weak hash_CVE-2026-10804

2 / 10
LOW
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.

Basic Information

ID CVE-2026-10804
Source VulDB
Published Jun 4, 2026 at 12:00

Affected Product

Vendor n/a
Product Streamlit
Version 1.0
Affected Versions n/a Streamlit 1.0
n/a Streamlit 1.1
n/a Streamlit 1.2
n/a Streamlit 1.3
n/a Streamlit 1.4
n/a Streamlit 1.5
n/a Streamlit 1.6
n/a Streamlit 1.7
n/a Streamlit 1.8
n/a Streamlit 1.9
n/a Streamlit 1.10
n/a Streamlit 1.11
n/a Streamlit 1.12
n/a Streamlit 1.13
n/a Streamlit 1.14
n/a Streamlit 1.15
n/a Streamlit 1.16
n/a Streamlit 1.17
n/a Streamlit 1.18
n/a Streamlit 1.19
n/a Streamlit 1.20
n/a Streamlit 1.21
n/a Streamlit 1.22
n/a Streamlit 1.23
n/a Streamlit 1.24
n/a Streamlit 1.25
n/a Streamlit 1.26
n/a Streamlit 1.27
n/a Streamlit 1.28
n/a Streamlit 1.29
n/a Streamlit 1.30
n/a Streamlit 1.31
n/a Streamlit 1.32
n/a Streamlit 1.33
n/a Streamlit 1.34
n/a Streamlit 1.35
n/a Streamlit 1.36
n/a Streamlit 1.37
n/a Streamlit 1.38
n/a Streamlit 1.39
n/a Streamlit 1.40
n/a Streamlit 1.41
n/a Streamlit 1.42
n/a Streamlit 1.43
n/a Streamlit 1.44
n/a Streamlit 1.45
n/a Streamlit 1.46
n/a Streamlit 1.47
n/a Streamlit 1.48
n/a Streamlit 1.49
n/a Streamlit 1.50
n/a Streamlit 1.51
n/a Streamlit 1.52
n/a Streamlit 1.53.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.