{"id":"CVE-2026-10804","summary":"Streamlit Palette hashing.py weak hash","details":"A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.","aliases":["GHSA-vqwp-45wm-r9r5","PYSEC-2026-212"],"modified":"2026-08-12T03:51:13.039764461Z","published":"2026-06-04T12:00:14.916Z","database_specific":{"cwe_ids":["CWE-327","CWE-328"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10804.json","cna_assigner":"VulDB"},"references":[{"type":"WEB","url":"https://github.com/streamlit/streamlit/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10804.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10804"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-10804"},{"type":"ADVISORY","url":"https://vuldb.com/submit/831508"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/368253"},{"type":"REPORT","url":"https://github.com/streamlit/streamlit/issues/14622"},{"type":"REPORT","url":"https://vuldb.com/vuln/368253/cti"},{"type":"FIX","url":"https://github.com/streamlit/streamlit/pull/14635"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/streamlit/streamlit","events":[{"introduced":"e819062f50119e3d5714d061f0a75104e16d45a7"},{"last_affected":"2e53b5bf7629c554ad94657d4783992c37b076ef"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:snowflake:streamlit:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.0"},{"last_affected":"1.0"},{"introduced":"1.1"},{"last_affected":"1.1"},{"introduced":"1.2"},{"last_affected":"1.2"},{"introduced":"1.3"},{"last_affected":"1.3"},{"introduced":"1.4"},{"last_affected":"1.4"},{"introduced":"1.5"},{"last_affected":"1.5"},{"introduced":"1.6"},{"last_affected":"1.6"},{"introduced":"1.7"},{"last_affected":"1.7"},{"introduced":"1.8"},{"last_affected":"1.8"},{"introduced":"1.9"},{"last_affected":"1.9"},{"introduced":"1.10"},{"last_affected":"1.10"},{"introduced":"1.11"},{"last_affected":"1.11"},{"introduced":"1.12"},{"last_affected":"1.12"},{"introduced":"1.13"},{"last_affected":"1.13"},{"introduced":"1.14"},{"last_affected":"1.14"},{"introduced":"1.15"},{"last_affected":"1.15"},{"introduced":"1.16"},{"last_affected":"1.16"},{"introduced":"1.17"},{"last_affected":"1.17"},{"introduced":"1.18"},{"last_affected":"1.18"},{"introduced":"1.19"},{"last_affected":"1.19"},{"introduced":"1.20"},{"last_affected":"1.20"},{"introduced":"1.21"},{"last_affected":"1.21"},{"introduced":"1.22"},{"last_affected":"1.22"},{"introduced":"1.23"},{"last_affected":"1.23"},{"introduced":"1.24"},{"last_affected":"1.24"},{"introduced":"1.25"},{"last_affected":"1.25"},{"introduced":"1.26"},{"last_affected":"1.26"},{"introduced":"1.27"},{"last_affected":"1.27"},{"introduced":"1.28"},{"last_affected":"1.28"},{"introduced":"1.29"},{"last_affected":"1.29"},{"introduced":"1.30"},{"last_affected":"1.30"},{"introduced":"1.31"},{"last_affected":"1.31"},{"introduced":"1.32"},{"last_affected":"1.32"},{"introduced":"1.33"},{"last_affected":"1.33"},{"introduced":"1.34"},{"last_affected":"1.34"},{"introduced":"1.35"},{"last_affected":"1.35"},{"introduced":"1.36"},{"last_affected":"1.36"},{"introduced":"1.37"},{"last_affected":"1.37"},{"introduced":"1.38"},{"last_affected":"1.38"},{"introduced":"1.39"},{"last_affected":"1.39"},{"introduced":"1.40"},{"last_affected":"1.40"},{"introduced":"1.41"},{"last_affected":"1.41"},{"introduced":"1.42"},{"last_affected":"1.42"},{"introduced":"1.43"},{"last_affected":"1.43"},{"introduced":"1.44"},{"last_affected":"1.44"},{"introduced":"1.45"},{"last_affected":"1.45"},{"introduced":"1.46"},{"last_affected":"1.46"},{"introduced":"1.47"},{"last_affected":"1.47"},{"introduced":"1.48"},{"last_affected":"1.48"},{"introduced":"1.49"},{"last_affected":"1.49"},{"introduced":"1.50"},{"last_affected":"1.50"},{"introduced":"1.51"},{"last_affected":"1.51"},{"introduced":"1.52"},{"last_affected":"1.52"},{"introduced":"1.53.0"},{"last_affected":"1.53.0"},{"introduced":"0"}]}}],"versions":["1.0","1.1","1.10","1.11","1.12","1.13","1.14","1.15","1.16","1.17","1.18","1.19","1.2","1.20","1.21","1.22","1.23","1.24","1.25","1.26","1.27","1.28","1.29","1.3","1.30","1.31","1.32","1.33","1.34","1.35","1.36","1.37","1.38","1.39","1.4","1.40","1.41","1.42","1.43","1.44","1.45","1.46","1.47","1.48","1.49","1.5","1.50","1.51","1.52","1.53.0","1.6","1.7","1.8","1.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10804.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}