VendorsLinux Foundationonnxall versions
Vulnerabilities

Linux Foundation ONNX (Open Neural Network Exchange)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2024-27319
Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.
Published 2024-02-23 · Modified
9.1EPSS 0.006
CVE-2026-28500
ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack
Published 2026-03-18 · Modified
9.1EPSS 0.003
CVE-2024-5187
Arbitrary File Overwrite in download_model_with_test_data in onnx/onnx
Published 2024-06-06 · Modified
8.8EPSS 0.012
CVE-2025-51480
Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions.
Published 2025-07-22 · Analyzed
8.8EPSS 0.006
CVE-2026-27489
ONNX: Path Traversal via Symlink
Published 2026-04-01 · Modified
8.7EPSS 0.006
CVE-2026-34445
ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
Published 2026-04-01 · Analyzed
8.6EPSS 0.003
CVE-2022-25882
Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"
Published 2023-01-25 · Modified
7.5EPSS 0.016
CVE-2024-27318
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.
Published 2024-02-23 · Modified
7.5EPSS 0.012
CVE-2026-49114
ONNX symlink-following and path-traversal arbitrary file write
Published 2026-08-21 · Analyzed
7.1EPSS 0.002
CVE-2026-34447
ONNX: External Data Symlink Traversal
Published 2026-04-01 · Analyzed
5.5EPSS 0.002
CVE-2026-44512
ONNX: Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)
Published 2026-07-08 · Analyzed
5.5EPSS 0.002
CVE-2026-34446
ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load
Published 2026-04-01 · Analyzed
5.5EPSS 0.002