---
id: CVE-2022-23594
aliases:
  - GHSA-9x52-887g-fhc2
  - BIT-tensorflow-2022-23594
  - PYSEC-2026-752
title: Out of bounds read in Tensorflow
summary: Out of bounds read in Tensorflow
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
vendor: tensorflow
product: tensorflow
ecosystem: pip
affected:
  - 'tensorflow >= 2.7.0, < 2.7.1'
  - 'tensorflow-cpu >= 2.7.0, < 2.7.1'
  - 'tensorflow-gpu >= 2.7.0, < 2.7.1'
patched:
  - tensorflow 2.7.1
  - tensorflow-cpu 2.7.1
  - tensorflow-gpu 2.7.1
published: '2022-02-09'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-9x52-887g-fhc2'
references:
  - url: >-
      https://github.com/tensorflow/tensorflow/security/advisories/GHSA-9x52-887g-fhc2
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2022-23594'
  - url: 'https://github.com/tensorflow/tensorflow'
  - url: >-
      https://github.com/tensorflow/tensorflow/tree/274df9b02330b790aa8de1cee164b70f72b9b244/tensorflow/core/ir/importexport
tags:
  - osv
  - pip
epss: 0.00144
epssPercentile: 0.03039
ingestedAt: '2026-07-08T18:25:48.116Z'
---

## Overview

### Impact
The [TFG dialect of TensorFlow (MLIR)](https://github.com/tensorflow/tensorflow/tree/274df9b02330b790aa8de1cee164b70f72b9b244/tensorflow/core/ir/importexport) makes several assumptions about the incoming `GraphDef` before converting it to the MLIR-based dialect.

If an attacker changes the `SavedModel` format on disk to invalidate these assumptions and the `GraphDef` is then converted to MLIR-based IR then they can cause a crash in the Python interpreter. Under certain scenarios, heap OOB read/writes are possible.
    
These issues have been discovered via fuzzing and it is possible that more weaknesses exist. We will patch them as they are discovered.
        
### Patches
We have patched the issue in multiple GitHub commits and these will be included in TensorFlow 2.8.0 and TensorFlow 2.7.1, as both are affected.
      
### For more information
Please consult [our security guide](https://github.com/tensorflow/tensorflow/blob/master/SECURITY.md) for more information regarding the security model and how to contact us with issues and questions.

## Affected packages

- `tensorflow >= 2.7.0, < 2.7.1`
- `tensorflow-cpu >= 2.7.0, < 2.7.1`
- `tensorflow-gpu >= 2.7.0, < 2.7.1`

## Remediation

Upgrade to a patched release:

- `tensorflow 2.7.1`
- `tensorflow-cpu 2.7.1`
- `tensorflow-gpu 2.7.1`
