CVE-2026-28500
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub.load() due to improper logic in the repository trust verification mechanism. While the function is designed to warn users when loading models from non-official sources, the use of the silent=True parameter completely suppresses all security warnings and confirmation prompts. This vulnerability transforms a standard model-loading function into a vector for Zero-Interaction Supply-Chain Attacks.
Leer descripción completaMostrar menos
When chained with file-system vulnerabilities, an attacker can silently exfiltrate sensitive files (SSH keys, cloud credentials) from the victim's machine the moment the model is loaded. As of time of publication, no known patched versions are available.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Puntuación base: 9.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.31%
- Percentil entre todas las CVEs puntuadas: 22
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1195Supply Chain Compromiseinitial access90 % - Impacto principal
T1005Data from Local Systemcollection85 % - Impacto secundario
T1068Exploitation for Privilege Escalationprivilege escalation75 % - Impacto secundario
T1552.001Credentials In Filescredential access80 %
Ataque a cadena de suministro: modelo ONNX manipulado distribuido via hub.load() con silent=True bypassa verificación de confianza. Exfiltración de datos (SSH, credenciales) y escalada local posibles.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-345, CWE-494, CWE-693
- CWE-829
Referencias
- https://github.com/ZeroXJacks/CVEs/blob/main/2026/CVE-2026-28500.md
- https://github.com/onnx/onnx/security/advisories/GHSA-hqmj-h5c6-369m
- https://access.redhat.com/errata/RHSA-2026:24977
- https://access.redhat.com/security/cve/CVE-2026-28500
- https://bugzilla.redhat.com/show_bug.cgi?id=2448518
- https://github.com/ZeroXJacks/CVEs/blob/main/2026/CVE-2026-28500.md
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28500.json
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-28500",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-28500",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-03-18T14:08:46.596652Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.6,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 3.9
},
{
"type": "Secondary",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.6,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "onnx",
"product": "onnx",
"versions": [
{
"status": "affected",
"version": "<= 1.20.1"
}
]
}
]
},
{
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"affectedData": [
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.25::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.25",
"versions": [
{
"status": "unaffected",
"version": "1780078312",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.25::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.25",
"versions": [
{
"status": "unaffected",
"version": "1780078429",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.25::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.25",
"versions": [
{
"status": "unaffected",
"version": "1780069222",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.25::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.25",
"versions": [
{
"status": "unaffected",
"version": "1780078632",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.25::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.25",
"versions": [
{
"status": "unaffected",
"version": "1780078416",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.25::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.25",
"versions": [
{
"status": "unaffected",
"version": "1780417775",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.25::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.25",
"versions": [
{
"status": "unaffected",
"version": "1780078388",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.25::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.25",
"versions": [
{
"status": "unaffected",
"version": "1780069146",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.25::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.25",
"versions": [
{
"status": "unaffected",
"version": "1780078413",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.25::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.25",
"versions": [
{
"status": "unaffected",
"version": "1780069226",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.25::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.25",
"versions": [
{
"status": "unaffected",
"version": "1780078629",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.25::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.25",
"versions": [
{
"status": "unaffected",
"version": "1780078414",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.25::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.25",
"versions": [
{
"status": "unaffected",
"version": "1780078632",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai:2.25::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI 2.25",
"versions": [
{
"status": "unaffected",
"version": "1780069222",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-openvino-model-server-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
}
]
}
],
"published": "2026-03-18T02:16:24.227",
"references": [
{
"url": "https://github.com/ZeroXJacks/CVEs/blob/main/2026/CVE-2026-28500.md",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/onnx/onnx/security/advisories/GHSA-hqmj-h5c6-369m",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:24977",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2026-28500",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448518",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://github.com/ZeroXJacks/CVEs/blob/main/2026/CVE-2026-28500.md",
"tags": [
"Patch"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
},
{
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28500.json",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-345"
},
{
"lang": "en",
"value": "CWE-494"
},
{
"lang": "en",
"value": "CWE-693"
}
]
},
{
"type": "Secondary",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"description": [
{
"lang": "en",
"value": "CWE-829"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub.load() due to improper logic in the repository trust verification mechanism. While the function is designed to warn users when loading models from non-official sources, the use of the silent=True parameter completely suppresses all security warnings and confirmation prompts. This vulnerability transforms a standard model-loading function into a vector for Zero-Interaction Supply-Chain Attacks. When chained with file-system vulnerabilities, an attacker can silently exfiltrate sensitive files (SSH keys, cloud credentials) from the victim's machine the moment the model is loaded. As of time of publication, no known patched versions are available."
},
{
"lang": "es",
"value": "Open Neural Network Exchange (ONNX) es un estándar abierto para la interoperabilidad de aprendizaje automático. En versiones hasta la 1.20.1 inclusive, existe un bypass de control de seguridad en onnx.hub.load() debido a una lógica incorrecta en el mecanismo de verificación de confianza del repositorio. Aunque la función está diseñada para advertir a los usuarios al cargar modelos de fuentes no oficiales, el uso del parámetro silent=True suprime completamente todas las advertencias de seguridad y las solicitudes de confirmación. Esta vulnerabilidad transforma una función estándar de carga de modelos en un vector para ataques de cadena de suministro de interacción cero. Cuando se encadena con vulnerabilidades del sistema de archivos, un atacante puede exfiltrar silenciosamente archivos sensibles (claves SSH, credenciales de la nube) de la máquina de la víctima en el momento en que se carga el modelo. Al momento de la publicación, no hay versiones parcheadas conocidas disponibles."
}
],
"lastModified": "2026-07-15T02:19:15.327",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:linuxfoundation:onnx:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "34920498-08A0-464E-B9F2-1562D29E3F26",
"versionEndIncluding": "1.20.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}