cbcvebase.
CVE-2026-34445
published 2026-04-01

CVE-2026-34445: Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was…

PriorityP351high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
EPSS
0.29%
21.0th percentile
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the "keys" in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianonnx
linuxfoundationonnx< 1.21.01.21.0
msrcazl3_pytorch_2.2.2-12_on_azure_linux_3.0
msrccbl2_pytorch_2.0.0-15_on_cbl_mariner_2.0
onnxonnx< 1.21.01.21.0
onnxonnx>= 0 < 1.21.01.21.0

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
osv8.6HIGH
vendor_debian8.6HIGH
vendor_msrc8.6HIGH
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.