Onnx
This hub aggregates every CVE we track for Onnx, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
11
CVEs tracked
1
Critical
7
High
0
In CISA KEV
Severity distribution
HIGH7MEDIUM3CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
1
0
0
0
1
0
0
0
0
0
0
0
1
4
0
0
2024-072026-06
Latest CVEs
The 11 most recently published vulnerabilities affecting Onnx.
- CVE-2026-34447ONNX: External Data Symlink Traversal5.5
- CVE-2026-34446ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load4.7
- CVE-2026-27489ONNX: Path Traversal via Symlink7.5
- CVE-2026-34445ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.8.6
- CVE-2026-28500ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack8.6
- CVE-2025-51480Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containin...8.8
- CVE-2024-7776Arbitrary File Overwrite in onnx/onnx9.1
- CVE-2024-5187Arbitrary File Overwrite in download_model_with_test_data in onnx/onnx8.8
- CVE-2024-27319Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.4.4
- CVE-2024-27318Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model ...7.5
- CVE-2022-25882Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current direct...7.5
Product normalization is registry-driven with AI assist and human review. How it works