Логотип exploitDog
bind:CVE-2026-24747
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-24747

Количество 5

Количество 5

ubuntu логотип

CVE-2026-24747

12 дней назад

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.load(..., weights_only=True)`, can corrupt memory and potentially lead to arbitrary code execution. Version 2.10.0 fixes the issue.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-24747

12 дней назад

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.load(..., weights_only=True)`, can corrupt memory and potentially lead to arbitrary code execution. Version 2.10.0 fixes the issue.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-24747

12 дней назад

PyTorch is a Python package that provides tensor computation. Prior to ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-63cw-57p8-fm3p

12 дней назад

PyTorch Vulnerable to Remote Code Execution via Untrusted Checkpoint Files

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2026-01224

5 месяцев назад

Уязвимость параметра weights_only функции torch.load() фреймворка машинного обучения PyTorch, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-24747

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.load(..., weights_only=True)`, can corrupt memory and potentially lead to arbitrary code execution. Version 2.10.0 fixes the issue.

CVSS3: 8.8
0%
Низкий
12 дней назад
nvd логотип
CVE-2026-24747

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.load(..., weights_only=True)`, can corrupt memory and potentially lead to arbitrary code execution. Version 2.10.0 fixes the issue.

CVSS3: 8.8
0%
Низкий
12 дней назад
debian логотип
CVE-2026-24747

PyTorch is a Python package that provides tensor computation. Prior to ...

CVSS3: 8.8
0%
Низкий
12 дней назад
github логотип
GHSA-63cw-57p8-fm3p

PyTorch Vulnerable to Remote Code Execution via Untrusted Checkpoint Files

CVSS3: 8.8
0%
Низкий
12 дней назад
fstec логотип
BDU:2026-01224

Уязвимость параметра weights_only функции torch.load() фреймворка машинного обучения PyTorch, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
0%
Низкий
5 месяцев назад

Уязвимостей на страницу