Skip to content

TorchServe security advisories

6 advisories · none critical or high in 12 months · latest Mar 20, 2025

6 advisories

DateAdvisory
Mar 202025TorchServe script references S3 bucket without ensuring ownership or confirming accessibility
CVE-2024-6577Medium6.3no fix yet
Jul 182024TorchServe gRPC Port Exposure
CVE-2024-35199High8.2fixed in 0.11.0
Jul 182024TorchServe vulnerable to bypass of allowed_urls configuration
CVE-2024-35198Critical9.8fixed in 0.11.0
Nov 212023TorchServe ZipSlip
CVE-2023-48299Medium5.3fixed in 0.9.0
Oct 22023TorchServe Server-Side Request Forgery vulnerability
CVE-2023-43654Critical9.8fixed in 0.8.2
Oct 22023TorchServe Pre-Auth Remote Code Execution
GHSA-4mqg-h5jf-j9m7Critical9.9fixed in 0.8.2
About TorchServe

Serving for PyTorch models.

Packages watched: torchserve (PyPI).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.