CVE-2024-31580High· 7.5▾ TwilightPyTorch heap buffer overflow vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 27.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
0.2% → 0.2%
PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
torch < 2.2.0Upgrade to a patched release:
torch 2.2.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-2953Low· 3.3PyTorch susceptible to local Denial of Service
CVE-2025-32434CriticalPyTorch: `torch.load` with `weights_only=True` leads to remote code execution
CVE-2025-3000Medium· 5.3PyTorch is vulnerable to memory corruption through its torch.jit.script function
CVE-2025-3730Low· 3.3PyTorch Improper Resource Shutdown or Release vulnerability
CVE-2025-3001NoneA vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulat…
CVE-2025-2999NoneA vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpa…