PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's readfromtensor callback that passes unclamped length to memcpy. Attackers can supply malicious or truncated GIF files to cause denial of service via segmentation fault or disclose adjacent heap memory contents.
{
"cna_assigner": "VulnCheck",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65918.json",
"cwe_ids": [
"CWE-125"
]
}"2026-07-25T08:12:07Z"
[
{
"target": {
"function": "decode_gif",
"file": "torchvision/csrc/io/image/cpu/decode_gif.cpp"
},
"id": "CVE-2026-65918-102aff36",
"digest": {
"function_hash": "112132269515122070679201174750253132581",
"length": 2687.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/pytorch/vision/commit/4e05dc22f5f050a9528cc0ea09ceca6cdaf8f4ed"
},
{
"target": {
"function": "read_from_tensor",
"file": "torchvision/csrc/io/image/cpu/decode_gif.cpp"
},
"id": "CVE-2026-65918-12665c40",
"digest": {
"function_hash": "280455404921887885591313047448875450975",
"length": 348.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/pytorch/vision/commit/4e05dc22f5f050a9528cc0ea09ceca6cdaf8f4ed"
},
{
"target": {
"function": "decode_gif",
"file": "torchvision/csrc/io/image/cpu/decode_gif.cpp"
},
"id": "CVE-2026-65918-1443da4d",
"digest": {
"function_hash": "112132269515122070679201174750253132581",
"length": 2687.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/pytorch/vision/commit/8fb87713a24951e639c494b0f2a8a81b5f8e33a6"
},
{
"target": {
"file": "torchvision/csrc/io/image/cpu/decode_gif.cpp"
},
"id": "CVE-2026-65918-918f85af",
"digest": {
"line_hashes": [
"287116950136699001826328110265274045585",
"241599930362376094676090232212194005682",
"51171007898239082412509034563661975000",
"279270508737142767250940464214616372129",
"262815012768025303260000722582759609967",
"26689528985233545659473290888660546493",
"15320229776471154267630209268125280188",
"126775920781419179365776900723565513340",
"32939749411153876891360162533780043152",
"34347866392657203696073342677444758757",
"120694394138037033245195067498717988613",
"150057024942589753093511323552547581327",
"86036999864605961883853931719903130984",
"184862781279256192962279724132253258026",
"319121864654706858116227764488291508619",
"141173664417298701392455715551165710818",
"63926407033617162061508760228572892092"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/pytorch/vision/commit/4e05dc22f5f050a9528cc0ea09ceca6cdaf8f4ed"
},
{
"target": {
"file": "torchvision/csrc/io/image/cpu/decode_gif.cpp"
},
"id": "CVE-2026-65918-bc06c681",
"digest": {
"line_hashes": [
"287116950136699001826328110265274045585",
"241599930362376094676090232212194005682",
"51171007898239082412509034563661975000",
"279270508737142767250940464214616372129",
"262815012768025303260000722582759609967",
"26689528985233545659473290888660546493",
"15320229776471154267630209268125280188",
"126775920781419179365776900723565513340",
"32939749411153876891360162533780043152",
"34347866392657203696073342677444758757",
"120694394138037033245195067498717988613",
"150057024942589753093511323552547581327",
"86036999864605961883853931719903130984",
"184862781279256192962279724132253258026",
"319121864654706858116227764488291508619",
"141173664417298701392455715551165710818",
"63926407033617162061508760228572892092"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/pytorch/vision/commit/8fb87713a24951e639c494b0f2a8a81b5f8e33a6"
},
{
"target": {
"function": "read_from_tensor",
"file": "torchvision/csrc/io/image/cpu/decode_gif.cpp"
},
"id": "CVE-2026-65918-c7fd9b23",
"digest": {
"function_hash": "280455404921887885591313047448875450975",
"length": 348.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/pytorch/vision/commit/8fb87713a24951e639c494b0f2a8a81b5f8e33a6"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-65918.json"