Linux / Onnx
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-49114 | ONNX symlink-following and path-traversal arbitrary file write | MEDIUM | 6.8 | Aug 21, 2026 |
| CVE-2026-44512 | ONNX: Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs) | MEDIUM | 6.5 | Jul 8, 2026 |
| CVE-2026-34447 | ONNX: External Data Symlink Traversal | MEDIUM | 5.5 | Apr 1, 2026 |
| CVE-2026-34446 | ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load | MEDIUM | 5.5 | Apr 1, 2026 |
| CVE-2026-27489 | ONNX: Path Traversal via Symlink | HIGH | 8.7 | Apr 1, 2026 |
| CVE-2026-34445 | ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings. | HIGH | 8.6 | Apr 1, 2026 |
| CVE-2026-28500 | ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack | CRITICAL | 9.1 | Mar 18, 2026 |
| CVE-2025-51480 | Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted… | HIGH | 8.8 | Jul 22, 2025 |
| CVE-2024-5187 | Arbitrary File Overwrite in download_model_with_test_data in onnx/onnx | HIGH | 8.8 | Jun 6, 2024 |
| CVE-2024-27319 | Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one… | CRITICAL | 9.1 | Feb 23, 2024 |
| CVE-2024-27318 | Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path t… | HIGH | 7.5 | Feb 23, 2024 |
| CVE-2022-25882 | Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file whi… | HIGH | 8.7 | Jan 25, 2023 |
Showing 1 to 12 of 12 CVEs