GHSA-wh2j-26j7-9728

Suggest an improvement
Source
https://github.com/advisories/GHSA-wh2j-26j7-9728
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-wh2j-26j7-9728/GHSA-wh2j-26j7-9728.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wh2j-26j7-9728
Aliases
  • CVE-2026-2473
Downstream
Related
Published
2026-02-20T21:31:24Z
Modified
2026-02-25T00:14:00.394363Z
Severity
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:Clear CVSS Calculator
Summary
Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
Details

Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting).

This vulnerability was patched and no customer action is needed.

Database specific
{
    "nvd_published_at": "2026-02-20T20:25:24Z",
    "github_reviewed_at": "2026-02-20T22:41:41Z",
    "github_reviewed": true,
    "severity": "HIGH",
    "cwe_ids": [
        "CWE-340"
    ]
}
References

Affected packages

PyPI / google-cloud-aiplatform

Package

Name
google-cloud-aiplatform
View open source insights on deps.dev
Purl
pkg:pypi/google-cloud-aiplatform

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.21.0
Fixed
1.133.0

Affected versions

1.*
1.21.0
1.22.0
1.22.1
1.23.0
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.28.0
1.28.1
1.29.0
1.30.0
1.30.1
1.31.0
1.31.1
1.32.0
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.36.1
1.36.2
1.36.3
1.36.4
1.37.0
1.38.0
1.38.1
1.39.0
1.40.0
1.41.0
1.42.0
1.42.1
1.43.0
1.44.0
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.50.0
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.0
1.59.0
1.60.0
1.61.0
1.62.0
1.63.0
1.64.0
1.65.0
1.66.0
1.67.0
1.67.1
1.68.0
1.69.0
1.70.0
1.71.0
1.71.1
1.72.0
1.73.0
1.74.0
1.75.0
1.76.0
1.77.0
1.78.0
1.79.0
1.80.0
1.81.0
1.82.0
1.83.0
1.84.0
1.85.0
1.86.0
1.87.0
1.88.0
1.89.0
1.90.0
1.91.0
1.92.0
1.93.0
1.93.1
1.94.0
1.95.0
1.95.1
1.96.0
1.97.0
1.98.0
1.99.0
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.131.0
1.132.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-wh2j-26j7-9728/GHSA-wh2j-26j7-9728.json"