{"id":"CVE-2024-35199","aliases":["GHSA-hhpg-v63p-wp7w","PYSEC-2026-1971"],"title":"TorchServe gRPC Port Exposure","summary":"TorchServe gRPC Port Exposure","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","vendor":"torchserve","product":"torchserve","ecosystem":"pip","affected":["torchserve >= 0.3.0, < 0.11.0"],"patched":["torchserve 0.11.0"],"published":"2024-07-18","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:16.759094781Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-hhpg-v63p-wp7w","references":[{"url":"https://github.com/pytorch/serve/security/advisories/GHSA-hhpg-v63p-wp7w"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35199"},{"url":"https://github.com/pytorch/serve/pull/3083"},{"url":"https://github.com/pytorch/serve/commit/aab99506a17193de217aacc1119d9381dbc6ed2b"},{"url":"https://github.com/pytorch/serve"},{"url":"https://github.com/pytorch/serve/releases/tag/v0.11.0"}],"tags":["osv","pip"],"epss":0.00637,"epssPercentile":0.48793,"ingestedAt":"2026-07-08T18:25:50.242Z","slug":"CVE-2024-35199","body":"## Overview\n\n### Impact\nThe two gRPC ports 7070 and 7071, are not bound to [localhost](http://localhost/) by default, so when TorchServe is launched, these two interfaces are bound to all interfaces. Customers using PyTorch inference Deep Learning Containers (DLC) through Amazon SageMaker and EKS are not affected.\n\n### Patches\nThis issue in TorchServe has been fixed in [#3083](https://github.com/pytorch/serve/pull/3083).\n\nTorchServe release 0.11.0 includes the fix to address this vulnerability.\n\n### References\n* [#3083](https://github.com/pytorch/serve/pull/3083)\n* [TorchServe release v0.11.0](https://github.com/pytorch/serve/releases/tag/v0.11.0)\n\nThank Kroll Cyber Risk for for responsibly disclosing this issue.\n\nIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.\n\n## Affected packages\n\n- `torchserve >= 0.3.0, < 0.11.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `torchserve 0.11.0`","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":45.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}