Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-34445

4 месяца назад

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the "keys" in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2026-34445

4 месяца назад

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the "keys" in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-34445

4 месяца назад

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the "keys" in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.

CVSS3: 8.6
EPSS: Низкий
msrc логотип

CVE-2026-34445

4 месяца назад

ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2026-34445

4 месяца назад

Open Neural Network Exchange (ONNX) is an open standard for machine le ...

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-538c-55jv-c5g9

4 месяца назад

ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-34445

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the "keys" in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.

CVSS3: 8.6
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-34445

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the "keys" in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.

CVSS3: 7.3
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-34445

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the "keys" in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.

CVSS3: 8.6
0%
Низкий
4 месяца назад
msrc логотип
CVE-2026-34445

ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.

CVSS3: 8.6
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-34445

Open Neural Network Exchange (ONNX) is an open standard for machine le ...

CVSS3: 8.6
0%
Низкий
4 месяца назад
github логотип
GHSA-538c-55jv-c5g9

ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.

CVSS3: 8.6
0%
Низкий
4 месяца назад

Уязвимостей на страницу