TorchServe security advisories
6 advisories · none critical or high in 12 months · latest Mar 20, 2025
6 advisories
| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | TorchServe script references S3 bucket without ensuring ownership or confirming accessibility CVE-2024-6577Medium6.3no fix yet | Medium6.3 | No fix yet |
| Jul 182024 | TorchServe gRPC Port Exposure CVE-2024-35199High8.2fixed in 0.11.0 | High8.2 | 0.11.0 |
| Jul 182024 | TorchServe vulnerable to bypass of allowed_urls configuration CVE-2024-35198Critical9.8fixed in 0.11.0 | Critical9.8 | 0.11.0 |
| Nov 212023 | TorchServe ZipSlip CVE-2023-48299Medium5.3fixed in 0.9.0 | Medium5.3 | 0.9.0 |
| Oct 22023 | TorchServe Server-Side Request Forgery vulnerability CVE-2023-43654Critical9.8fixed in 0.8.2 | Critical9.8 | 0.8.2 |
| Oct 22023 | TorchServe Pre-Auth Remote Code Execution GHSA-4mqg-h5jf-j9m7Critical9.9fixed in 0.8.2 | Critical9.9 | 0.8.2 |