Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3876
  • PyPI/onnx
ONNX: TOCTOU arbitrary file read/write in save_external_dat 10 Sep
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-3587
  • PyPI/onnx
ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape 04 Aug
  • Fix available
  • Severity - 3.3 (Low)
GHSA-p893-rvq9-2xf9
  • PyPI/onnx
ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape 24 Jul
  • Fix available
  • Severity - 3.3 (Low)
PYSEC-2026-2689
  • PyPI/onnx
ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs) 13 Jul
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-hwpq-hmq9-wj77
  • PyPI/onnx
ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs) 07 Jul
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-q56x-g2fj-4rj6
  • PyPI/onnx
ONNX: TOCTOU arbitrary file read/write in save_external_dat 01 Apr
  • Fix available
  • Severity - 7.1 (High)
GHSA-p433-9wv8-28xj
  • PyPI/onnx
ONNX: External Data Symlink Traversal 01 Apr
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-cmw6-hcpp-c6jp
  • PyPI/onnx
ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load 01 Apr
  • Fix available
  • Severity - 4.7 (Medium)
GHSA-538c-55jv-c5g9
  • PyPI/onnx
ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings. 01 Apr
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-104
  • PyPI/onnx
See record for full details 01 Apr
  • Fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-2241
  • PyPI/onnx
See record for full details 01 Apr
  • Fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-2240
  • PyPI/onnx
See record for full details 01 Apr
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-2239
  • PyPI/onnx
See record for full details 01 Apr
  • Fix available
  • Severity - 7.5 (High)
GHSA-3r9x-f23j-gc73
  • PyPI/onnx
onnx Vulnerable to Path Traversal via Symlink 31 Mar
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-103
  • PyPI/onnx
See record for full details 18 Mar
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-hqmj-h5c6-369m
  • PyPI/onnx
ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack 16 Mar
  • Fix available
  • Severity - 8.6 (High)