Home/Product/linuxfoundation onnx
Product

linuxfoundation onnx

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-34447
< 1.21.0
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a
5.5MEDIUM
CVE-2026-34446
< 1.21.0
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a
4.7MEDIUM
CVE-2026-34445
< 1.21.0
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the Extern
8.6HIGH
CVE-2026-27489
< 1.21.0
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path tra
7.5HIGH
CVE-2026-28500
<= 1.20.1
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.2
8.6HIGH
CVE-2025-51480
all versions
Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrar
8.8HIGH
CVE-2024-7776
<= 1.16.1
A vulnerability in the download_model function of the onnx/onnx framework, before and including version 1.16.1, allows for arbit
9.1CRITICAL
CVE-2024-5187
all versions
A vulnerability in the download_model_with_test_data function of the onnx/onnx framework, version 1.16.0, allows for arbitrary f
8.8HIGH
CVE-2024-27319
< 1.16.0
Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM
4.4MEDIUM
CVE-2024-27318
< 1.16.0
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the t
7.5HIGH
CVE-2022-25882
< 1.13.0
Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto ca
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin