---
id: CVE-2021-4118
aliases:
  - GHSA-2vj5-px25-gjrp
  - PYSEC-2021-874
  - PYSEC-2026-3968
title: pytorch-lightning is vulnerable to Deserialization of Untrusted Data
summary: pytorch-lightning is vulnerable to Deserialization of Untrusted Data
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
vendor: pytorch-lightning
product: pytorch-lightning
ecosystem: pip
affected:
  - pytorch-lightning < 1.6.0
patched:
  - pytorch-lightning 1.6.0
published: '2022-01-06'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T17:26:03.425101162Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-2vj5-px25-gjrp'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-4118'
  - url: 'https://github.com/PyTorchLightning/pytorch-lightning/issues/11045'
  - url: 'https://github.com/PyTorchLightning/pytorch-lightning/pull/11099'
  - url: >-
      https://github.com/pytorchlightning/pytorch-lightning/commit/62f1e82e032eb16565e676d39e0db0cac7e34ace
  - url: 'https://github.com/PyTorchLightning/pytorch-lightning/releases/tag/1.6.0'
  - url: 'https://github.com/advisories/GHSA-2vj5-px25-gjrp'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/pytorch-lightning/PYSEC-2021-874.yaml
  - url: 'https://github.com/pytorchlightning/pytorch-lightning'
  - url: 'https://huntr.dev/bounties/31832f0c-e5bb-4552-a12c-542f81f111e6'
tags:
  - osv
  - pip
epss: 0.00978
epssPercentile: 0.60539
ingestedAt: '2026-09-12T03:13:01.640Z'
---

## Overview

pytorch-lightning is vulnerable to Deserialization of Untrusted Data.

## Affected packages

- `pytorch-lightning < 1.6.0`

## Remediation

Upgrade to a patched release:

- `pytorch-lightning 1.6.0`
