Known Vulnerabilities for Pytorch by Linuxfoundation
Listed below are 4 of the newest known vulnerabilities associated with "Pytorch" by "Linuxfoundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-58659 json | PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state f... | Not Provided | 2026-07-15 | 2026-07-18 |
| CVE-2026-56340 json | vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorc... | Not Provided | 2026-06-20 | 2026-07-15 |
| CVE-2026-53875 json | picklescan before 1.0.3 contains a scanning bypass vulnerability in the scan_pytorch function that allows attackers to embed ... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-47749 json | stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, a... | Not Provided | 2026-06-16 | 2026-06-16 |
| CVE-2026-47748 json | stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, a... | Not Provided | 2026-06-16 | 2026-06-16 |
| CVE-2026-44484 json | PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced f... | Not Provided | 2026-05-14 | 2026-07-15 |
| CVE-2026-31250 json | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerabilit... | Not Provided | 2026-05-11 | 2026-05-12 |
| CVE-2026-31249 json | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerabilit... | Not Provided | 2026-05-11 | 2026-05-12 |
| CVE-2026-31238 json | The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. When sta... | Not Provided | 2026-05-12 | 2026-05-14 |
| CVE-2026-31228 json | The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow component... | Not Provided | 2026-05-12 | 2026-07-15 |