Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

onnx — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting onnx. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ONNX serves as an open format for machine learning models, enabling interoperability across frameworks. Historically, vulnerabilities have included remote code execution, buffer overflows, and improper input validation, often stemming from insecure parsing of model files. While no major public incidents have been widely documented, the 9 recorded CVEs highlight potential risks in model processing and serialization. Security characteristics include reliance on third-party runtime environments and dependencies, which may introduce additional attack surfaces. Proper validation of untrusted models remains critical to prevent exploitation, as malformed inputs could lead to arbitrary code execution or system compromise.

Top products by onnx: onnx onnx/onnx onnx-mlir
CVE ID Title CVSS Severity Published
CVE-2026-49114 ONNX symlink-following and path-traversal arbitrary file write — ONNX CWE-367 7.1 High 2026-08-21
CVE-2026-63632 ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape — onnx CWE-125 3.3 Low 2026-08-18
CVE-2026-44512 ONNX: Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs) — onnx CWE-476 5.5 Medium 2026-07-08
CVE-2026-11329 onnx onnx-mlir Placeholder Node Cache backend.py generate_hash_key weak hash — onnx-mlir CWE-328 3.6 Low 2026-06-05
CVE-2026-34447 ONNX: External Data Symlink Traversal — onnx CWE-61 5.5 Medium 2026-04-01
CVE-2026-34446 ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load — onnx CWE-22 4.7 Medium 2026-04-01
CVE-2026-27489 ONNX: Path Traversal via Symlink — onnx CWE-23 5.5AI Medium AI 2026-04-01
CVE-2026-34445 ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings. — onnx CWE-20 8.6 High 2026-04-01
CVE-2026-28500 ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack — onnx CWE-345 8.6 High 2026-03-18
CVE-2024-7776 Arbitrary File Overwrite in onnx/onnx — onnx/onnx CWE-22 9.8 - 2025-03-20
CVE-2024-5187 Arbitrary File Overwrite in download_model_with_test_data in onnx/onnx — onnx/onnx CWE-22 8.8AI High AI 2024-06-06
CVE-2024-27319 Open Neural Network Exchange 缓冲区错误漏洞 — onnx CWE-125 4.4 Medium 2024-02-23
CVE-2024-27318 Open Neural Network Exchange 安全漏洞 — onnx CWE-22 7.5 High 2024-02-23

This page lists every published CVE security advisory associated with onnx. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.