# CVE-2026-10804

## Summary

- **CVE ID:** CVE-2026-10804
- **Severity:** LOW
- **CVSS Score:** 3.6 (CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P)
- **CWE:** CWE-328, CWE-327
- **Published:** Jun 4, 2026
- **Last Modified:** Jun 4, 2026

## Description

A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.

## Affected Products

- n/a — Streamlit (1.0)
- n/a — Streamlit (1.1)
- n/a — Streamlit (1.2)
- n/a — Streamlit (1.3)
- n/a — Streamlit (1.4)
- n/a — Streamlit (1.5)
- n/a — Streamlit (1.6)
- n/a — Streamlit (1.7)
- n/a — Streamlit (1.8)
- n/a — Streamlit (1.9)
- n/a — Streamlit (1.10)
- n/a — Streamlit (1.11)
- n/a — Streamlit (1.12)
- n/a — Streamlit (1.13)
- n/a — Streamlit (1.14)
- n/a — Streamlit (1.15)
- n/a — Streamlit (1.16)
- n/a — Streamlit (1.17)
- n/a — Streamlit (1.18)
- n/a — Streamlit (1.19)
- n/a — Streamlit (1.20)
- n/a — Streamlit (1.21)
- n/a — Streamlit (1.22)
- n/a — Streamlit (1.23)
- n/a — Streamlit (1.24)
- n/a — Streamlit (1.25)
- n/a — Streamlit (1.26)
- n/a — Streamlit (1.27)
- n/a — Streamlit (1.28)
- n/a — Streamlit (1.29)
- n/a — Streamlit (1.30)
- n/a — Streamlit (1.31)
- n/a — Streamlit (1.32)
- n/a — Streamlit (1.33)
- n/a — Streamlit (1.34)
- n/a — Streamlit (1.35)
- n/a — Streamlit (1.36)
- n/a — Streamlit (1.37)
- n/a — Streamlit (1.38)
- n/a — Streamlit (1.39)
- n/a — Streamlit (1.40)
- n/a — Streamlit (1.41)
- n/a — Streamlit (1.42)
- n/a — Streamlit (1.43)
- n/a — Streamlit (1.44)
- n/a — Streamlit (1.45)
- n/a — Streamlit (1.46)
- n/a — Streamlit (1.47)
- n/a — Streamlit (1.48)
- n/a — Streamlit (1.49)
- n/a — Streamlit (1.50)
- n/a — Streamlit (1.51)
- n/a — Streamlit (1.52)
- n/a — Streamlit (1.53.0)

## References

- [CNA](https://vuldb.com/vuln/368253)
- [CNA](https://vuldb.com/vuln/368253/cti)
- [CNA](https://vuldb.com/cve/CVE-2026-10804)
- [CNA](https://vuldb.com/submit/831508)
- [CNA](https://github.com/streamlit/streamlit/issues/14622)
- [CNA](https://github.com/streamlit/streamlit/pull/14635)
- [CNA](https://github.com/streamlit/streamlit/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.08%
- **EPSS Percentile:** 0.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._