All 3 CVE vulnerabilities found in tract, with AI-generated Chinese analysis, references, and POCs.
Vendor: sonos
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-55093 | tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load CWE-125 | 6.1 | Medium | 2026-09-14 |
| CVE-2026-55832 | Tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnx CWE-22 | 6.1 | Medium | 2026-09-14 |
| CVE-2026-75093 | sonos tract ONNX Initializer Loader tensor.rs from_raw_dt_align buffer size CWE-131 | 4.3 | Medium | 2026-08-18 |
All 3 known CVE vulnerabilities affecting tract with full Chinese analysis, references, and POCs where available.