Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

tensorflow — Vulnerabilities & Security Advisories 403

Browse all 403 CVE security advisories affecting tensorflow. AI-powered Chinese analysis, POCs, and references for each vulnerability.

TensorFlow is an open-source machine learning framework primarily used for developing and deploying data flow graphs across various platforms. With 403 recorded Common Vulnerabilities and Exposures (CVEs), it has historically been susceptible to a wide array of security flaws. These incidents frequently involve remote code execution, buffer overflows, and denial-of-service conditions, often stemming from improper input validation or memory management errors within its C++ backend. While cross-site scripting is less common due to its backend nature, privilege escalation risks exist when the framework runs with elevated system permissions. Notable security characteristics include its complex dependency tree, which can introduce indirect vulnerabilities through third-party libraries. Major incidents have largely focused on exploitation of parsing routines and model serialization processes, highlighting the critical need for rigorous patch management and secure configuration practices in production environments to mitigate these persistent risks.

Top products by tensorflow: tensorflow keras
CVE ID Title CVSS Severity Published
CVE-2026-2492 TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability — TensorFlow CWE-427 7.8AI High AI 2026-02-20
CVE-2023-33976 TensorFlow segfault in array_ops.upper_bound — tensorflow CWE-190 7.5 High 2024-07-30
CVE-2024-3660 Arbitrary code injection vulnerability in Keras framework < 2.13 — keras 9.8AI Critical AI 2024-04-16
CVE-2023-25661 Denial of Service in TensorFlow — tensorflow CWE-20 6.5 Medium 2023-03-27
CVE-2023-25660 TensorFlow vulnerable to seg fault in `tf.raw_ops.Print` — tensorflow CWE-476 7.5 High 2023-03-24
CVE-2023-25659 TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch — tensorflow CWE-125 7.5 High 2023-03-24
CVE-2023-25658 TensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGrad — tensorflow CWE-125 7.5 High 2023-03-24
CVE-2023-25662 TensorFlow vulnerable to integer overflow in EditDistance — tensorflow CWE-190 7.5 High 2023-03-24
CVE-2023-25663 TensorFlow has Null Pointer Error in TensorArrayConcatV2 — tensorflow CWE-476 7.5 High 2023-03-24
CVE-2023-25664 TensorFlow vulnerable to Heap Buffer Overflow in AvgPoolGrad — tensorflow CWE-120 7.5 High 2023-03-24
CVE-2023-25667 TensorFlow vulnerable to segfault when opening multiframe gif — tensorflow CWE-190 6.5 Medium 2023-03-24
CVE-2023-25666 TensorFlow has Floating Point Exception in AudioSpectrogram — tensorflow CWE-697 7.5 High 2023-03-24
CVE-2023-25665 TensorFlow has Null Pointer Error in SparseSparseMaximum — tensorflow CWE-476 7.5 High 2023-03-24
CVE-2023-25668 TensorFlow vulnerable to heap out-of-buffer read in the QuantizeAndDequantize operation — tensorflow CWE-122 9.8 Critical 2023-03-24
CVE-2023-25669 TensorFlow has Floating Point Exception in AvgPoolGrad with XLA — tensorflow CWE-697 7.5 High 2023-03-24
CVE-2023-25670 TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize — tensorflow CWE-476 7.5 High 2023-03-24
CVE-2023-25671 TensorFlow has segmentation fault in tfg-translate — tensorflow CWE-787 7.5 High 2023-03-24
CVE-2023-25672 TensorFlow has Null Pointer Error in LookupTableImportV2 — tensorflow CWE-476 7.5 High 2023-03-24
CVE-2023-25673 TensorFlow has Floating Point Exception in TensorListSplit with XLA — tensorflow CWE-697 7.5 High 2023-03-24
CVE-2023-25674 TensorFlow has Null Pointer Error in RandomShuffle with XLA enable — tensorflow CWE-476 7.5 High 2023-03-24
CVE-2023-25675 TensorFlow has Segfault in Bincount with XLA — tensorflow CWE-697 7.5 High 2023-03-24
CVE-2023-25676 TensorFlow has null dereference on ParallelConcat with XLA — tensorflow CWE-476 7.5 High 2023-03-24
CVE-2023-25801 TensorFlow has double free in Fractional(Max/Avg)Pool — tensorflow CWE-415 8.0 High 2023-03-24
CVE-2023-27579 TensorFlow has Floating Point Exception in TFLite in conv kernel — tensorflow CWE-697 7.5 High 2023-03-24
CVE-2022-41910 Heap out of bounds read in `QuantizeAndDequantizeV2` in Tensorflow — tensorflow CWE-125 4.8 Medium 2022-12-06
CVE-2022-41902 Out of bounds write in grappler in Tensorflow — tensorflow CWE-787 7.1 High 2022-12-06
CVE-2022-41890 `CHECK` fail in `BCast` overflow in Tensorflow — tensorflow CWE-704 4.8 Medium 2022-11-18
CVE-2022-41888 Unckecked rank size in `tf.image.generate_bounding_box_proposals` in Tensorflow — tensorflow CWE-20 4.8 Medium 2022-11-18
CVE-2022-41889 Segfault via invalid attributes in `pywrap_tfe_src.cc` in Tensorflow — tensorflow CWE-476 5.5 Medium 2022-11-18
CVE-2022-41887 Overflow in `tf.keras.losses.poisson` in Tensorflow — tensorflow CWE-131 4.8 Medium 2022-11-18

This page lists every published CVE security advisory associated with tensorflow. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.