Skip to content

ONNX security advisories

13 advisories · 4 critical or high in 12 months · latest Jul 24

13 advisories

DateAdvisory
Jul 24ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape
CVE-2026-63632Low3.3fixed in 1.22.0
Jul 7ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)
CVE-2026-44512Medium5.5fixed in 1.22.0
Apr 1ONNX: TOCTOU arbitrary file read/write in save_external_dat
CVE-2026-49114High7.1fixed in 1.21.0
Apr 1ONNX: External Data Symlink Traversal
CVE-2026-34447Medium5.5fixed in 1.21.0
Apr 1ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load
CVE-2026-34446Medium4.7fixed in 1.21.0
Apr 1ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
CVE-2026-34445High8.6fixed in 1.21.0
Mar 31onnx Vulnerable to Path Traversal via Symlink
CVE-2026-27489Highfixed in 1.21.0
Mar 16ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() , Silent Supply-Chain Attack
CVE-2026-28500High8.6fixed in 1.21.0rc1
Mar 202025Open Neural Network Exchange (ONNX) Path Traversal Vulnerability
CVE-2024-7776High8.1fixed in 1.17.0
Jun 62024onnx allows Arbitrary File Overwrite in download_model_with_test_data
CVE-2024-5187High8.8fixed in 1.16.2
Feb 232024Onnx Out-of-bounds Read vulnerability
CVE-2024-27319Medium4.4fixed in 1.16.0
Feb 232024Onnx Directory Traversal vulnerability
CVE-2024-27318High7.5fixed in 1.16.0
Jan 262023Directory Traversal in onnx
CVE-2022-25882High7.5fixed in 1.13.0
About ONNX

The open model format (LF AI and Data).

Packages watched: onnx (PyPI).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.