CVE-2026-25211: Llamastack Llama Stack

Low severity, CVSS 3.2. EPSS: 0.2% chance of exploitation in the next 30 days.

Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.

Affected products

  • Llamastack Llama Stack: before 0.4.0rc3 (fixed in 0.4.0rc3)

Published 2026-01-30. Last modified 2026-06-17.