---
id: CVE-2025-2999
aliases:
  - PYSEC-2025-193
  - BIT-pytorch-2025-2999
  - GHSA-vgrw-7cvw-pwgx
title: >-
  A vulnerability was found in PyTorch 2.6.0. It has been rated as critical.
  Affected by this issue is the function torch.nn.utils.rnn.unpa…
summary: >-
  A vulnerability was found in PyTorch 2.6.0. It has been rated as critical.
  Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The
  manipulation leads to memory corruption. Attacking locally is a requirement.
  The ex…
severity: none
vendor: torch
product: torch
ecosystem: pip
affected:
  - torch <= 2.6.0-NA
published: '2025-03-31'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2025-193'
references:
  - url: 'https://vuldb.com/?id.302048'
  - url: 'https://vuldb.com/?submit.524198'
  - url: 'https://github.com/pytorch/pytorch/issues/149622'
  - url: 'https://github.com/pytorch/pytorch/issues/149622#issue-2935495265'
  - url: 'https://vuldb.com/?ctiid.302048'
  - url: 'https://github.com/advisories/GHSA-vgrw-7cvw-pwgx'
tags:
  - osv
  - pip
epss: 0.00198
epssPercentile: 0.09891
ingestedAt: '2026-07-13T18:58:06.499Z'
---

## Overview

A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

## Affected packages

- `torch <= 2.6.0-NA`

## Remediation

Refer to the advisory for the patched release.
