Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

PyTorch — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in PyTorch, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known software weaknesses and vulnerabilities associated with the PyTorch deep learning framework developed by Meta Platforms. It serves as a central resource for understanding the security posture of this widely used open-source machine learning library. The collection includes a comprehensive range of vulnerability types found within the PyTorch ecosystem, covering critical issues such as buffer overflows, improper input validation, path traversal flaws, and insecure default configurations. These entries encompass both direct vulnerabilities within the core PyTorch codebase and issues affecting its primary dependencies. The historical data covers security disclosures dating back to the project's early public releases, providing a longitudinal view of stability and remediation practices over time. This time range allows analysts to observe patterns in vulnerability introduction and resolution across different major release cycles. Visitors can use this resource to track specific vendor advisories from Meta and the broader PyTorch community regarding security patches and mitigation strategies. Users may also analyze how specific weakness classes, such as those defined in Common Weakness Enumeration, manifest within this particular technology stack. Furthermore, the page facilitates a deeper look into the product’s vulnerability history, enabling developers and security engineers to assess the impact of past flaws on current versions and determine the necessity of upgrades or configuration changes. This information supports informed decision-making for organizations integrating PyTorch into their production environments, helping them prioritize patching efforts based on risk severity and exposure.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-4538 PyTorch pt2 Loading deserialization CWE-502 5.3 Medium 2026-03-22
CVE-2026-24747 PyTorch Vulnerable to Remote Code Execution via Untrusted Checkpoint Files CWE-502 8.8 High 2026-01-27
CVE-2025-4287 PyTorch nccl.py torch.cuda.nccl.reduce denial of service CWE-404 3.3 Low 2025-05-05
CVE-2025-32434 PyTorch: `torch.load` with `weights_only=True` leads to remote code execution CWE-502 8.8 - 2025-04-18
CVE-2025-3730 PyTorch LossCTC.cpp torch.nn.functional.ctc_loss denial of service CWE-404 3.3 Low 2025-04-16
CVE-2025-3136 PyTorch CUDACachingAllocator.cpp torch.cuda.memory.caching_allocator_delete memory corruption CWE-119 3.3 Low 2025-04-03
CVE-2025-3121 PyTorch torch.jit.jit_module_from_flatbuffer memory corruption CWE-119 3.3 Low 2025-04-02
CVE-2025-3001 PyTorch torch.lstm_cell memory corruption CWE-119 5.3 Medium 2025-03-31
CVE-2025-3000 PyTorch torch.jit.script memory corruption CWE-119 5.3 Medium 2025-03-31
CVE-2025-2999 PyTorch torch.nn.utils.rnn.unpack_sequence memory corruption CWE-119 5.3 Medium 2025-03-31
CVE-2025-2998 PyTorch torch.nn.utils.rnn.pad_packed_sequence memory corruption CWE-119 5.3 Medium 2025-03-31
CVE-2025-2953 PyTorch torch.mkldnn_max_pool2d denial of service CWE-404 3.3 Low 2025-03-30
CVE-2025-2149 PyTorch Quantized Sigmoid Module nnq_Sigmoid initialization CWE-665 2.5 Low 2025-03-10
CVE-2025-2148 PyTorch Tuple torch.ops.profiler._call_end_callbacks_on_jit_fut memory corruption CWE-119 5.0 Medium 2025-03-10

All 14 known CVE vulnerabilities affecting PyTorch with full Chinese analysis, references, and POCs where available.