© 2025-2026 PySpect
First version without a known vulnerability: 2.13.0
A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request but has not reacted yet.
PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.load(..., weights_only=True)`, can corrupt memory and potentially lead to arbitrary code execution. Version 2.10.0 fixes the issue.
Fixed in: 2.10.0
An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (DoS).
An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.
Fixed in: 2.7.1
A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a Denial of Service (DoS).
Fixed in: 2.7.1
A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).
Fixed in: 2.7.1
pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
Fixed in: 2.9.0
A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
Fixed in: 2.7.1
pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.
Fixed in: 2.9.0
An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.
Fixed in: 2.9.0
PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, and nn.Dropout3d for fallback_random=True.
Fixed in: 2.7.0
In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.
Fixed in: 2.7.0
In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.
Fixed in: 2.7.0
In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.
Fixed in: 2.7.0
In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.
Fixed in: 2.7.0
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
Fixed in: 2.6.0
PyTorch Improper Resource Shutdown or Release vulnerability
Fixed in: 2.8.0
A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
PyTorch is vulnerable to memory corruption through its torch.lstm_cell function
Fixed in: 2.10.0
PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function
PyTorch is vulnerable to memory corruption through its torch.jit.script function
Fixed in: 2.13.0
PyTorch is vulnerable to memory corruption through its unpack_sequence function
Fixed in: 2.9.1
PyTorch susceptible to local Denial of Service
Fixed in: 2.7.1-rc1
PyTorch: Manipulation of the argument scale/zero_point leads to improper initialization via Quantized Sigmoid Module
PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument
In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
Fixed in: 2.5.0
Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp.
Fixed in: 7c35874ad664e74c8e4252d67521f3986eadb0e6, 2.2.0
PyTorch heap buffer overflow vulnerability
Fixed in: 2.2.0, b5c3a17c2c207ebefcb85043f0cf94be9b2fef81
Pytorch use-after-free vulnerability
Fixed in: 2.2.0, 9c7071b0e324f9fb68ab881283d6b8d388a4bcd2
PyTorch vulnerable to arbitrary code execution
Fixed in: 1.13.1, 767f6aa49fe20a2766b9843d01e3b7f7793df6a3