Skip to content
pytorch-lightningGHSA-2vj5-px25-gjrp

pytorch-lightning is vulnerable to Deserialization of Untrusted Data

High7.8CVE-2021-4118 · Published Jan 6, 2022 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
pytorch-lightning
PyPI
< 1.6.01.6.0
Details and references

More pytorch-lightning advisories

All
DateAdvisory
Mar 62022Code Injection in PyTorch Lightning
CVE-2022-0845Critical9.8fixed in 1.6.0
Mar 202025PyTorch Lightning path traversal vulnerability
CVE-2024-8019Critical9.1fixed in 2.4.0
Mar 202025PyTorch Lightning denial of service vulnerability
CVE-2024-8020High7.5no fix yet
May 7Compromise of PyTorch Lightning PyPi Package Versions
CVE-2026-44484Critical9.8no fix yet
May 12PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
CVE-2026-31221High7.8no fix yet
Jul 15PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass we
CVE-2026-58659High7.8fixed in 2.6.6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.