Pytorch
Pytorch Torch: vulnerabilities and CVEs
Pytorch Torch has 13 published vulnerabilities, 11 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs13
Last 12 months11
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71281 | High (8.8) | 0.50% | — | Aug 5, 2026 | Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src/peft/tuners/lora/loraga.py line ~101) call torch.load on config-specified cache/covariance files… |
| CVE-2025-71369 | High (7.6) | 0.56% | — | Jul 4, 2026 | picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basichandlers in reduce methods, allowing attackers to bypass safety checks. Remote attackers can embed… |
| CVE-2025-71356 | High (7.6) | 0.38% | — | Jul 4, 2026 | picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression function calls in pickle files. Attackers can embed undetected code in pickle files that… |
| CVE-2025-71353 | High (7.6) | 0.38% | — | Jul 4, 2026 | picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in reduce methods. Attackers can craft pickle files with embedded code that evades picklescan… |
| CVE-2025-71345 | High (7.6) | 0.54% | — | Jul 4, 2026 | picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can embed undetected code in pickle files that executes during… |
| CVE-2025-71350 | High (7.6) | 0.45% | — | Jun 30, 2026 | picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded… |
| CVE-2025-71370 | High (7.6) | 0.48% | — | Jun 23, 2026 | picklescan before 0.0.28 fails to detect malicious torch.jit.unsupported_tensor_ops.execWrapper function calls embedded in pickle files. Attackers can craft malicious pickle files that bypass picklescan detection and… |
| CVE-2026-31229 | Critical (9.8) | 0.88% | — | May 12, 2026 | The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model loading functionality. When loading model weights from a file (e.g.,… |
| CVE-2026-31219 | High (8.8) | 0.80% | — | May 12, 2026 | The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CWE-502). When a user… |
| CVE-2026-31218 | High (8.8) | 0.80% | — | May 12, 2026 | The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CWE-502). When loading… |
| CVE-2026-31214 | Critical (9.8) | 0.88% | — | May 12, 2026 | The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insecure deserialization vulnerability (CWE-502). The script uses… |
| CVE-2025-4701 | Medium (4.8) | 0.20% | — | May 15, 2025 | A vulnerability, which was classified as problematic, has been found in VITA-MLLM Freeze-Omni up to 20250421. This issue affects the function torch.load of the file models/utils.py. The manipulation of the argument path… |
| CVE-2024-12029 | Critical (9.8) | 6.0% | — | Mar 20, 2025 | A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability arises from unsafe deserialization of model files using torch.load… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.