{"data":{"id":"377c842c-b1d4-47be-b623-9382dc197de2","title":"CVE-2026-55093: Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1","summary":"Tract, a toolkit for running machine learning models (TensorFlow and ONNX inference, which means executing pre-trained AI models), has a vulnerability in how it handles tensor dimensions (the sizes of data arrays). Before versions 0.21.16, 0.22.2, and 0.23.1, an attacker could craft a malicious model file that tricks Tract into allocating a small amount of memory while actually trying to access a much larger area, potentially exposing nearby data in memory or crashing the program.","solution":"This issue is fixed in versions 0.21.16, 0.22.2, and 0.23.1.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55093","publishedAt":"2026-09-14T20:16:47.290Z","cveId":"CVE-2026-55093","cweIds":["CWE-125","CWE-190"],"cvssScore":"6.1","cvssSeverity":"medium","severity":"medium","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Tract"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","attackVector":"local","attackComplexity":"low","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-14T20:16:47.290Z","capecIds":["CAPEC-540"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","availability"],"aiComponentTargeted":"inference","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}