CVE-2026-49114
- EPSS 0.11%
- Veröffentlicht 21.08.2026 16:17:17
- Zuletzt bearbeitet 21.08.2026 17:16:31
In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check. A local attac...
CVE-2026-63632
- EPSS 0.17%
- Veröffentlicht 18.08.2026 14:55:15
- Zuletzt bearbeitet 18.08.2026 19:16:59
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter...
CVE-2026-44512
- EPSS 0.18%
- Veröffentlicht 08.07.2026 19:32:04
- Zuletzt bearbeitet 13.07.2026 17:02:01
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.convert_version() can dereference a null pointer in Upsample_6_7::adapt_upsample_6_7() in onnx/version_con...
CVE-2026-14647
- EPSS 0.25%
- Veröffentlicht 04.07.2026 19:00:11
- Zuletzt bearbeitet 06.07.2026 19:16:56
A weakness has been identified in onnx up to 1.21.x. This vulnerability affects the function convPoolShapeInference_opset19 of the file onnx/defs/nn/old.cc of the component onnxruntime. This manipulation causes out-of-bounds read. It is possible to i...
CVE-2026-34447
- EPSS 0.25%
- Veröffentlicht 01.04.2026 17:39:38
- Zuletzt bearbeitet 15.04.2026 14:45:48
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a symlink traversal vulnerability in external data loading allows reading files outside the model directory. This issue h...
CVE-2026-34446
- EPSS 0.18%
- Veröffentlicht 01.04.2026 17:37:54
- Zuletzt bearbeitet 15.04.2026 15:03:15
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is an issue in onnx.load, the code checks for symlinks to prevent path traversal, but completely misses hardlinks because a ...
CVE-2026-27489
- EPSS 0.59%
- Veröffentlicht 01.04.2026 17:33:51
- Zuletzt bearbeitet 15.07.2026 02:19:07
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory. This issue has...
CVE-2026-34445
- EPSS 0.29%
- Veröffentlicht 01.04.2026 17:30:19
- Zuletzt bearbeitet 15.04.2026 15:08:13
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) direct...
CVE-2026-28500
- EPSS 0.32%
- Veröffentlicht 18.03.2026 01:15:07
- Zuletzt bearbeitet 15.07.2026 02:19:15
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub.load() due to improper logic in the repository trust verification mech...
CVE-2025-51480
- EPSS 0.58%
- Veröffentlicht 22.07.2025 00:00:00
- Zuletzt bearbeitet 08.10.2025 13:11:30
Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory r...