pytorch-lightningGHSA-2vj5-px25-gjrp
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
High7.8CVE-2021-4118 · Published Jan 6, 2022 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| pytorch-lightning PyPI | < 1.6.0 | 1.6.0 |
Details and references
pytorch-lightning is vulnerable to Deserialization of Untrusted Data.
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-502
- Also known as
- CVE-2021-4118, PYSEC-2021-874, PYSEC-2026-3968
- nvd.nist.gov/vuln/detail/CVE-2021-4118
- github.com/PyTorchLightning/pytorch-lightning/issues/11045
- github.com/PyTorchLightning/pytorch-lightning/pull/11099
- github.com/pytorchlightning/pytorch-lightning/commit/62f1e82e032eb16565e676d39e0db0cac7e34ace
- github.com/PyTorchLightning/pytorch-lightning/releases/tag/1.6.0
- github.com/advisories/GHSA-2vj5-px25-gjrp
- github.com/pypa/advisory-database/tree/main/vulns/pytorch-lightning/PYSEC-2021-874.yaml
- github.com/pytorchlightning/pytorch-lightning
- huntr.dev/bounties/31832f0c-e5bb-4552-a12c-542f81f111e6
More pytorch-lightning advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 62022 | Code Injection in PyTorch Lightning CVE-2022-0845Critical9.8fixed in 1.6.0 | Critical9.8 | 1.6.0 |
| Mar 202025 | PyTorch Lightning path traversal vulnerability CVE-2024-8019Critical9.1fixed in 2.4.0 | Critical9.1 | 2.4.0 |
| Mar 202025 | PyTorch Lightning denial of service vulnerability CVE-2024-8020High7.5no fix yet | High7.5 | No fix yet |
| May 7 | Compromise of PyTorch Lightning PyPi Package Versions CVE-2026-44484Critical9.8no fix yet | Critical9.8 | No fix yet |
| May 12 | PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization CVE-2026-31221High7.8no fix yet | High7.8 | No fix yet |
| Jul 15 | PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass we CVE-2026-58659High7.8fixed in 2.6.6 | High7.8 | 2.6.6 |