CVE-2026-34446General(linuxfoundation / onnx)

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is an issue in onnx.load, the code checks for symlinks to prevent path traversal, but completely misses hardlinks because a hardlink looks exactly like a regular file on the filesystem. This issue has been patched in version 1.21.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-61

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • onnx

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-02)
  • 3 total mentions across 2 days

Affected systems

Products
onnx

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-01: 1Mentions · 2026-04-02: 2Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 204-0104-02
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-011
General1
2026-04-022
Disclosure1General1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-34446 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is an issue in onnx.load, the code check… https://www.cve.org/CVERecord?id=CVE-2026-34446 ----- Traducción: CVE-2026-34446 Ope… http://infoflow.cloud`

    Post summary

    The tweet shares CVE‑2026‑34446 for ONNX, noting a defect in onnx.load before v1.21.0, and links to the CVE record, without offering exploiting code or mitigation details.

    0000040
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34446 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is an issue in onnx.load, the code check… https://www.cve.org/CVERecord?id=CVE-2026-34446

    Post summary

    The post references CVE‑2026‑34446, noting an issue with ONNX’s onnx.load before version 1.21.0, but it does not provide PoC, exploit code, or mention patches or active exploitation.

    00000247
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-34446 - ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load Intel Report: https://ift.tt/D5X1U9z

    Post summary

    A newly disclosed CVE‑2026‑34446 involves an arbitrary file read via a hardlink bypass in ONNX. No PoC, exploit code, active exploitation, or patch information is provided.

    0000044
    281 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationonnx---

Explore more