Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-538c-55jv-c5g9

Опубликовано: 01 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 8.6

Описание

ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.

Summary

The ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. The problem? It didn’t check if the "keys" in the file were valid. Because it blindly trusted the file, an attacker could craft a malicious model that overwrites internal object properties.

Why its Dangerous

Instant Crash DoS: An attacker can set the length property to a massive number like 9 petabytes. When the system tries to load the model, it attempts to allocate all that RAM at once, causing the server to crash or freeze Out of Memory.

Access Bypass: By setting a negative offset -1, an attacker can trick the system into reading parts of a file it wasn't supposed to touch.

Object Corruption: Attackers can even inject "dunder" attributes like class to change the object's type entirely, which could lead to more complex exploits.

Fixed: https://github.com/onnx/onnx/pull/7751 object state corruption and DoS via ExternalDataInfo attribute injection

Пакеты

Наименование

onnx

pip
Затронутые версииВерсия исправления

<= 1.20.1

1.21.0

EPSS

Процентиль: 21%
0.00288
Низкий

8.6 High

CVSS3

Дефекты

CWE-20
CWE-400
CWE-915

Связанные уязвимости

CVSS3: 8.6
ubuntu
4 месяца назад

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the "keys" in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.

CVSS3: 7.3
redhat
4 месяца назад

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the "keys" in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.

CVSS3: 8.6
nvd
4 месяца назад

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the "keys" in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.

CVSS3: 8.6
msrc
4 месяца назад

ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.

CVSS3: 8.6
debian
4 месяца назад

Open Neural Network Exchange (ONNX) is an open standard for machine le ...

EPSS

Процентиль: 21%
0.00288
Низкий

8.6 High

CVSS3

Дефекты

CWE-20
CWE-400
CWE-915