Skip to content

PyTorch security advisories

31 advisories · 2 critical or high in 12 months · latest Mar 22

31 advisories

DateAdvisory
Mar 22A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project w
CVE-2026-4538High7.8no fix yet
Jan 27PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.load(..., weights_only=True)`, can corrupt memory and potentiall
CVE-2026-24747High8.8fixed in 2.10.0
Nov 122025An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (DoS).
CVE-2025-63396Low3.3no fix yet
Sep 252025An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.
CVE-2025-55560High7.5fixed in 2.7.1
Sep 252025pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.
CVE-2025-55552High7.5fixed in 2.9.0
Sep 252025A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
CVE-2025-55553High7.5fixed in 2.7.1
Sep 252025pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
CVE-2025-55554Medium5.3fixed in 2.9.0
Sep 252025A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).
CVE-2025-55557High7.5fixed in 2.7.1
Sep 252025A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a Denial of Service (DoS).
CVE-2025-55558High7.5fixed in 2.7.1
Sep 252025In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.
CVE-2025-46148Medium5.3fixed in 2.7.0
Sep 252025In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.
CVE-2025-46149Medium5.3fixed in 2.7.0
Sep 252025In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.
CVE-2025-46150Medium5.3fixed in 2.7.0
Sep 252025In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.
CVE-2025-46152Medium5.3fixed in 2.7.0
Sep 252025PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, and nn.Dropout3d for fallback_random=True.
CVE-2025-46153Medium5.3fixed in 2.7.0
Sep 252025An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.
CVE-2025-55551High7.5fixed in 2.9.0
Apr 182025PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
CVE-2025-32434Criticalfixed in 2.6.0
Apr 162025PyTorch Improper Resource Shutdown or Release vulnerability
CVE-2025-3730Medium3.3fixed in 2.8.0
Apr 32025A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. The manipulation leads to memory corruption. An attack has to be approached locally. The ex
CVE-2025-3136Low3.3no fix yet
Apr 22025A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
CVE-2025-3121Medium5.5no fix yet
Mar 312025PyTorch is vulnerable to memory corruption through its torch.lstm_cell function
CVE-2025-3001Low5.3fixed in 2.10.0
Mar 312025PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function
CVE-2025-2998Medium5.3no fix yet
Mar 312025PyTorch is vulnerable to memory corruption through its torch.jit.script function
CVE-2025-3000Low5.3fixed in 2.13.0
Mar 312025PyTorch is vulnerable to memory corruption through its unpack_sequence function
CVE-2025-2999Medium5.3fixed in 2.9.1
Mar 302025PyTorch susceptible to local Denial of Service
CVE-2025-2953Low3.3fixed in 2.7.1-rc1
Mar 102025PyTorch: Manipulation of the argument scale/zero_point leads to improper initialization via Quantized Sigmoid Module
CVE-2025-2149Low2.5no fix yet
Mar 102025PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument
CVE-2025-2148Low5.0no fix yet
Oct 292024In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
CVE-2024-48063Critical9.8fixed in 2.5.0
Apr 192024Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp.
CVE-2024-31584Medium5.5fixed in 2.2.0
Apr 172024PyTorch heap buffer overflow vulnerability
CVE-2024-31580High7.5fixed in 2.2.0
Apr 172024Pytorch use-after-free vulnerability
CVE-2024-31583High7.8fixed in 2.2.0
Nov 262022PyTorch vulnerable to arbitrary code execution
CVE-2022-45907Critical9.8fixed in 1.13.1
About PyTorch

The open-source machine learning framework (PyTorch Foundation).

Packages watched: torch (PyPI).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.