Skip to content
PyTorchGHSA-887c-mr87-cxwp

PyTorch Improper Resource Shutdown or Release vulnerability

Medium3.3CVE-2025-3730 · Published Apr 16, 2025 · updated Sep 10, 2026

A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The name of the patch is 46fc5d8e360127361211cb237d5f9eef0223e567. It is recommended to apply a patch to fix this issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
torch
PyPI
< 2.8.02.8.0
Details and references

More PyTorch advisories

All PyTorch
Advisory
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
CriticalApr 18, 2025
PyTorch: memory corruption
Low3.3Apr 3, 2025
PyTorch: memory corruption
Medium5.5Apr 2, 2025
PyTorch is vulnerable to memory corruption through its torch.lstm_cell function
Low5.3Mar 31, 2025
PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function
Medium5.3Mar 31, 2025
PyTorch is vulnerable to memory corruption through its torch.jit.script function
Low5.3Mar 31, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.