← Retour aux CVEs
CVE-2026-34445
HIGH8.6
Description
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the "keys" in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.
Details CVE
Score CVSS v3.18.6
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie4/1/2026
Derniere modification4/3/2026
Sourcenvd
Observations honeypot0
Faiblesses (CWE)
CWE-20CWE-400CWE-915
References
https://github.com/onnx/onnx/commit/e30c6935d67cc3eca2fa284e37248e7c0036c46b(security-advisories@github.com)
https://github.com/onnx/onnx/pull/7751(security-advisories@github.com)
https://github.com/onnx/onnx/security/advisories/GHSA-538c-55jv-c5g9(security-advisories@github.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.