---
id: CVE-2026-87083
title: A weakness has been identified in tile-ai tilelang up to 0.1.14
summary: >-
  A weakness has been identified in tile-ai tilelang up to 0.1.14. This impacts
  the function KernelCache._load_kernel_from_disk of the file
  tilelang/cache/kernel_cache.py of the component Kernel Cache. Executing a
  manipulation can lead to …
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L'
cwe:
  - CWE-20
  - CWE-502
vendor: tile-ai
product: tilelang
affected:
  - tilelang 0.1.0
  - tilelang 0.1.1
  - tilelang 0.1.2
  - tilelang 0.1.3
  - tilelang 0.1.4
  - tilelang 0.1.5
  - tilelang 0.1.6
  - tilelang 0.1.7
  - tilelang 0.1.8
  - tilelang 0.1.9
  - tilelang 0.1.10
  - tilelang 0.1.11
  - tilelang 0.1.12
  - tilelang 0.1.13
  - tilelang 0.1.14
published: '2026-09-09'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T16:17:14.890'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87083'
references:
  - url: 'https://github.com/tile-ai/tilelang/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/tile-ai/tilelang/commit/11ec2397fe942e8b422d026af4a03d6e0a55ae6c
    label: cna@vuldb.com
  - url: 'https://github.com/tile-ai/tilelang/issues/2817'
    label: cna@vuldb.com
  - url: 'https://github.com/tile-ai/tilelang/pull/3143'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-87083'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/911126'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/400289'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/400289/cti'
    label: cna@vuldb.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87083.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-87083'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2530476'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-87083'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87083'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-09T15:37:57.801940Z'
epss: 0.00345
epssPercentile: 0.25375
ingestedAt: '2026-09-09T02:19:39.649Z'
---

## Overview

A weakness has been identified in tile-ai tilelang up to 0.1.14. This impacts the function KernelCache._load_kernel_from_disk of the file tilelang/cache/kernel_cache.py of the component Kernel Cache. Executing a manipulation can lead to deserialization. The attack may be performed from remote. This patch is called 11ec2397fe942e8b422d026af4a03d6e0a55ae6c. Applying a patch is advised to resolve this issue. Based on the release information, the fix has not been included in any official release yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat OpenShift AI (RHOAI) · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87083.json)
