CVE-2025-55559

Severity
7.5HIGH
EPSS
0.1%
top 81.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 25

Description

An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDgoogle/tensorflow2.18.0

🔴Vulnerability Details

3
OSV
CVE-2025-55559: An issue was discovered TensorFlow v22025-09-25
GHSA
GHSA-49v8-592x-2x5p: An issue was discovered TensorFlow v22025-09-25
CVEList
CVE-2025-55559: An issue was discovered TensorFlow v22025-09-25

📋Vendor Advisories

2
Red Hat
tensorflow: Conv2D with 'valid' padding causes XLA compile crash leading to denial of service2025-09-25
Debian
CVE-2025-55559: tensorflow - An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs whe...2025
CVE-2025-55559 (HIGH CVSS 7.5) | An issue was discovered TensorFlow | cvebase.io