Skip to content
pytorch-lightningGHSA-98fp-7v67-4v3q

PyTorch Lightning denial of service vulnerability

High7.5CVE-2024-8020 · Published Mar 20, 2025 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
pytorch-lightning
PyPI
<= 2.3.2No fix yet
Details and references

A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the `/api/v1/state` endpoint of `LightningApp`. This issue occurs due to improper handling of unexpected state values, which results in the server shutting down.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-248
Also known as
CVE-2024-8020, PYSEC-2026-1857, PYSEC-2026-3971

More pytorch-lightning advisories

All

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.