onnx vulnerabilities
CVEs whose affected-version data names the onnx package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
11 CVEsRSS
GHSA-486p-g8x4-77mgMedium· 7.1Duplicate Advisory: ONNX: TOCTOU arbitrary file read/write in save_external_dat
Duplicate Advisory: ONNX: TOCTOU arbitrary file read/write in save_external_dat
CVE-2026-49114High· 7.1In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check
In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check. …
CVE-2026-63632Low· 3.3Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/vers…
CVE-2026-44512Medium· 5.5ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)
ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)
CVE-2026-34447Medium· 5.5ONNX: External Data Symlink Traversal
ONNX: External Data Symlink Traversal
CVE-2026-34446Medium· 4.7ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load
ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load
CVE-2026-34445High· 8.6ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
CVE-2026-27489Highonnx Vulnerable to Path Traversal via Symlink
onnx Vulnerable to Path Traversal via Symlink
CVE-2026-28500High· 8.6ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack
ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack
CVE-2024-27318High· 7.5Onnx Directory Traversal vulnerability
Onnx Directory Traversal vulnerability
CVE-2024-27319Medium· 4.4Onnx Out-of-bounds Read vulnerability
Onnx Out-of-bounds Read vulnerability