Amazon · Gluonts · CVE-2026-100308
**Name of the Vulnerable Software and Affected Versions**
Amazon GluonTS versions prior to 0.17.0
**Description**
Deserialization of untrusted data in the model loading component allows context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process by using a crafted serialized model directory.
**Recommendations**
Upgrade to version 0.17.0 or later.