tract vulnerabilities
CVEs whose affected-version data names the tract package (rust). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-55832Medium· 6.1PoCTract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit
Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2, the tract-onnx crate passes the attacker-controlled external_data location from an ONNX model through onnx/src/tens…
▾ Twilightsonos · tractEPSS 0.24%via NVD
CVE-2026-55093Medium· 6.1PoCTract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit
Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1, tract-nnef uses unchecked usize multiplication in nnef/src/tensors.rs read_tensor for attacker-controlled tensor di…
▾ Twilightsonos · tractEPSS 0.20%via NVD