CVE-2026-4538
published 2026-03-22CVE-2026-4538: A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to…
PriorityP345high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.1th percentile
A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request but has not reacted yet.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pytorch | — | — |
| linuxfoundation | pytorch | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.3MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:P
osv4.8MEDIUM
vendor_debian4.8MEDIUM
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
PyTorch 2.10.0 pt2 Loading deserialization (ID 176791 / EUVD-2026-14280)
vuldb·2026-05-05·CVSS 1.9
CVE-2026-4538 [LOW] PyTorch 2.10.0 pt2 Loading deserialization (ID 176791 / EUVD-2026-14280)
A vulnerability, which was classified as critical, has been found in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization.
This vulnerability is referenced as CVE-2026-4538. The attack can only be performed from a local environment. Furthermore, an exploit is available.
The project was informed of the problem early through a pull request but has not reacted yet.
OSV
CVE-2026-4538: A vulnerability was identified in PyTorch 2
osv·2026-03-22·CVSS 4.8
CVE-2026-4538 [MEDIUM] CVE-2026-4538: A vulnerability was identified in PyTorch 2
A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request but has not reacted yet.
GHSA
GHSA-33x2-ppm4-v46v: A vulnerability was identified in PyTorch 2
ghsa_unreviewed·2026-03-22
CVE-2026-4538 [MEDIUM] CWE-20 GHSA-33x2-ppm4-v46v: A vulnerability was identified in PyTorch 2
A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request but has not reacted yet.
Red Hat
pytorch: PyTorch: Deserialization vulnerability in pt2 Loading Handler allows local impact
vendor_redhat·2026-03-22·CVSS 4.8
CVE-2026-4538 [MEDIUM] CWE-502 pytorch: PyTorch: Deserialization vulnerability in pt2 Loading Handler allows local impact
pytorch: PyTorch: Deserialization vulnerability in pt2 Loading Handler allows local impact
A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request but has not reacted yet.
A flaw was found in PyTorch. A local user can exploit a deserialization vulnerability within an unknown function of the `pt2 Loading Handler` component. This flaw could allow for information disclosure, data manipulation, or denial of service.
Package: rhaiis/vllm-cpu-rhel9 (Red Hat AI Inference Server) - Not affected
Pack
Debian
CVE-2026-4538: pytorch - A vulnerability was identified in PyTorch 2.10.0. The affected element is an unk...
vendor_debian·2026·CVSS 4.8
CVE-2026-4538 [MEDIUM] CVE-2026-4538: pytorch - A vulnerability was identified in PyTorch 2.10.0. The affected element is an unk...
A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request but has not reacted yet.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
2026-03-22
Published