CVE-2026-3071: Flair

High severity, CVSS 8.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when loading a malicious model.

Affected products

Published 2026-02-26. Last modified 2026-06-17.