CVE-2026-34445Disclosure(linuxfoundation / onnx)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linuxfoundation onnx systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the "keys" in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-400CWE-915

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • onnx

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-02); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
onnx

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-02: 2Mentions · 2026-04-05: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-05: 1Technical Details · 2026-04-02: 2Technical Details · 2026-04-05: 104-0204-05
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-022
Disclosure1Patch1
2026-04-051
Disclosure1
Full discourse3 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    Vulnerability (CVE-2026-34445) in `ONNX` processing can crash servers via malicious models. Review input validation and harden object settings. #ONNX #CyberSecurity #DoS https://www.pulsepatch.io/posts/cve-2026-34445-onnx-model-processing-dos

    Post summary

    CVE-2026-34445 is a DoS vulnerability in ONNX processing that can crash servers via malicious models; users are advised to validate input and harden object settings.

    0000034
    4 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34445: HIGH] Update your ONNX to version 1.21.0. Previous versions allowed potential cyber attacks by not validating model data, enabling overwriting properties.#cve,CVE-2026-34445,#cybersecurity https://cvefind.com/CVE-2026-34445

    Post summary

    The post advertises a high‑severity CVE (CVE‑2026‑34445) affecting ONNX prior to v1.21.0 due to insufficient model data validation and urges users to update to the patched version.

    0000031
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-34445 - High Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() funct... https://www.thehackerwire.com/vulnerability/CVE-2026-34445/ https://t.co/cuQHnHz5L1

    Post summary

    The message announces a high‑severity vulnerability in ONNX prior to version 1.21.0, giving basic technical context but no PoC, exploit, or patch details.

    0000036
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationonnx---

Explore more