torchserve vulnerabilities
CVEs whose affected-version data names the torchserve package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2024-6577Medium· 6.3TorchServe script references S3 bucket without ensuring ownership or confirming accessibility
TorchServe script references S3 bucket without ensuring ownership or confirming accessibility
▾ Sunlittorchserve · torchserveEPSS 0.39%via OSV
CVE-2024-35198Critical· 9.8TorchServe vulnerable to bypass of allowed_urls configuration
TorchServe vulnerable to bypass of allowed_urls configuration
▾ Midnighttorchserve · torchserveEPSS 0.80%via OSV
CVE-2024-35199High· 8.2TorchServe gRPC Port Exposure
TorchServe gRPC Port Exposure
▾ Twilighttorchserve · torchserveEPSS 0.64%via OSV
CVE-2023-48299Medium· 5.3TorchServe ZipSlip
TorchServe ZipSlip
▾ Sunlittorchserve · torchserveEPSS 0.68%via OSV
CVE-2023-43654Critical· 9.8PoCTorchServe Server-Side Request Forgery vulnerability
TorchServe Server-Side Request Forgery vulnerability
▾ Abyssaltorchserve · torchserveEPSS 36%via OSV