Skip to content
PyTorchPYSEC-2025-206

pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().

Medium5.3CVE-2025-55554 · Published Sep 25, 2025 · updated May 20, 2026

Source advisory

Affected versions

PackageAffectedFixed in
torch
PyPI
< 2.9.02.9.0
Details and references

pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Severity from
the CVSS score
Also known as
BIT-pytorch-2025-55554, CVE-2025-55554

More PyTorch advisories

All PyTorch

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.