Onnx
15 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Onnx, a product in the ai ml space. Use it to gauge the current risk picture and drill into individual advisories.
Onnx CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 1 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 5 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 1 |
| 2026-08 | 2 |
| 2026-09 | 0 |
Severity
How the 15 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High8
- Medium4
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Onnx.
- CVE-2026-49114ONNX symlink-following and path-traversal arbitrary file write7.1
- CVE-2026-63632ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape3.3
- CVE-2026-44512ONNX: Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)5.5
- GHSA-q56x-g2fj-4rj6ONNX: TOCTOU arbitrary file read/write in save_external_dat —
- CVE-2026-34447ONNX: External Data Symlink Traversal5.5
- CVE-2026-34446ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load4.7
- CVE-2026-27489ONNX: Path Traversal via Symlink7.5
- CVE-2026-34445ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.8.6
- CVE-2026-28500ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack8.6
- CVE-2025-51480Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containin...8.8
- CVE-2024-7776Arbitrary File Overwrite in onnx/onnx9.1
- CVE-2024-5187Arbitrary File Overwrite in download_model_with_test_data in onnx/onnx8.8
- CVE-2024-27319Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.4.4
- CVE-2024-27318Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model ...7.5
- CVE-2022-25882Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current direct...7.5
Product grouping is registry-driven, with AI assist and human review. How it works