/r/netsec@_r_netsecDisclosure
The advisory announces CVE-2026-28500, a high‑severity flaw in ONNX Hub that disables trust checks, allowing supply chain attacks, and notes that no patch is currently available; it provides technical details but no PoC or exploit.
Security Harvester@secharvesterxDisclosure
The advisory discloses CVE-2026-28500, a high‑severity flaw in ONNX Hub that disables trust verification via silent=True, permitting supply‑chain attacks, with no patch currently available.
The Hacker Wire@TheHackerWireDisclosure
CVE-2026-28500 is a high‑severity security control bypass in ONNX hub.load() affecting releases up to 1.20.1, with no known exploits, patches, or PoC indicated in the brief.
CVE@CVEnewGeneral
The text is a brief announcement of a security control bypass in ONNX versions up to 1.20.1, without additional details or actionable information.
PulsePatch.io@pulsepatchioDisclosure
CVEs 2026-28500 discloses a silent model loading flaw in ONNX that poses a supply‑chain risk; while a PoC link is provided, no exploitation or patch is mentioned.
Secwiser - Cyber Security Insights@SecwiserappPatch
The advisory explains CVE-2026-28500, detailing how silent=True bypasses trust verification in ONNX hub.load and recommends mitigations, though no official patch exists.
CVEarity@CVEarityDisclosure
The tweet announces CVE‑2026‑28500 with a high severity score but provides no technical details, PoC, or patch information.
CVEFind.com@CveFindComDisclosure
The post announces a high‑severity vulnerability (CVE‑2026‑28500) in ONNX 1.20.1 and earlier that allows bypassing trust verification, enabling potential zero‑interaction supply‑chain attacks; no patches or exploit code are mentioned.