CVE-2026-34447Disclosure(linuxfoundation / onnx)

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a symlink traversal vulnerability in external data loading allows reading files outside the model directory. This issue has been patched in version 1.21.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-61

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • onnx

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-02)
  • 3 total mentions across 2 days

Affected systems

Products
onnx

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-01: 1Mentions · 2026-04-02: 2Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 204-0104-02
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-011
Disclosure1
2026-04-022
Disclosure2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34447 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a symlink traversal vulnerability in … https://www.cve.org/CVERecord?id=CVE-2026-34447 ----- Traducción: CVE-2026-34447 Ope… http://infoflow.cloud`

    Post summary

    The tweet announces a symlink traversal bug in ONNX versions prior to 1.21.0, providing a link to the official CVE record for further details.

    0000036
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34447 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a symlink traversal vulnerability in … https://www.cve.org/CVERecord?id=CVE-2026-34447

    Post summary

    The passage announces a symlink traversal issue in ONNX versions before 1.21.0, providing basic vulnerability details but no PoC, exploit, active use, or remediation information.

    00000228
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-34447 - ONNX: External Data Symlink Traversal Intel Report: https://ift.tt/Zi8yz2H

    Post summary

    The alert announces the CVE-2026-34447 vulnerability in ONNX, labeling it as an External Data Symlink Traversal, but offers no PoC, exploit details, patch information, or evidence of active exploitation.

    0000042
    281 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationonnx---

Explore more