CVE-2025-2953Low· 3.3▾ SunlitPyTorch susceptible to local Denial of Service
▾ Sunlit zone — Low / medium · no exploitation signal
impact 18.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
torch < 2.7.1-rc1Upgrade to a patched release:
torch 2.7.1-rc1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-32434CriticalPyTorch: `torch.load` with `weights_only=True` leads to remote code execution
CVE-2024-31580High· 7.5PyTorch heap buffer overflow vulnerability
CVE-2025-3000Medium· 5.3PyTorch is vulnerable to memory corruption through its torch.jit.script function
CVE-2025-3730Low· 3.3PyTorch Improper Resource Shutdown or Release vulnerability
CVE-2025-3001NoneA vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulat…
CVE-2025-2999NoneA vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpa…