{"data":{"ecosystem":"pypi","name":"torch","url":"https://aisecwatch.com/packages/pypi/torch","latestVersion":"2.14.1","firstReleaseAt":"2018-12-07T18:56:01.203Z","repository":"https://github.com/pytorch/pytorch","llm":{"exposure":"none","depth":null,"integratedAt":null,"integratedVersion":null,"sdks":[],"path":[]},"authority":{"profile":[],"fromDependencies":[]},"dependencies":[{"ecosystem":"pypi","name":"cuda-bindings","versionSpec":"<14,>=13.0.3","scope":"runtime"},{"ecosystem":"pypi","name":"cuda-toolkit","versionSpec":"==13.0.3","scope":"runtime"},{"ecosystem":"pypi","name":"filelock","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"fsspec","versionSpec":">=0.8.5","scope":"runtime"},{"ecosystem":"pypi","name":"jinja2","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"networkx","versionSpec":">=2.5.1","scope":"runtime"},{"ecosystem":"pypi","name":"nvidia-cudnn-cu13","versionSpec":"==9.24.0.43","scope":"runtime"},{"ecosystem":"pypi","name":"nvidia-cusparselt-cu13","versionSpec":"==0.8.1","scope":"runtime"},{"ecosystem":"pypi","name":"nvidia-nccl-cu13","versionSpec":"==2.30.7","scope":"runtime"},{"ecosystem":"pypi","name":"nvidia-nvshmem-cu13","versionSpec":"==3.4.5","scope":"runtime"},{"ecosystem":"pypi","name":"opt-einsum","versionSpec":">=3.3","scope":"extra:opt-einsum"},{"ecosystem":"pypi","name":"optree","versionSpec":">=0.13.0","scope":"extra:optree"},{"ecosystem":"pypi","name":"pyyaml","versionSpec":null,"scope":"extra:pyyaml"},{"ecosystem":"pypi","name":"setuptools","versionSpec":">=77.0.3","scope":"runtime"},{"ecosystem":"pypi","name":"sympy","versionSpec":">=1.13.3","scope":"runtime"},{"ecosystem":"pypi","name":"triton","versionSpec":"~=3.8.0","scope":"runtime"},{"ecosystem":"pypi","name":"typing-extensions","versionSpec":">=4.10.0","scope":"runtime"}],"advisories":[{"id":"ec9bd69e-2209-4956-800a-fdbaf5506646","url":"https://aisecwatch.com/issues/ec9bd69e-2209-4956-800a-fdbaf5506646","cveId":"CVE-2025-32434","title":"CVE-2025-32434: PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks…","headline":"PyTorch remote command execution when loading models with torch.load","severity":"critical","publishedAt":"2025-04-18T20:15:23.183Z","affected":["torch@< 2.6.0 (fixed: 2.6.0)"],"epssScore":0.02187},{"id":"8f9e49a6-05c0-4546-899c-cb48e5e1b3d0","url":"https://aisecwatch.com/issues/8f9e49a6-05c0-4546-899c-cb48e5e1b3d0","cveId":"CVE-2025-3730","title":"CVE-2025-3730: A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function…","headline":"PyTorch denial of service in ctc_loss via local manipulation","severity":"low","publishedAt":"2025-04-17T01:15:48.700Z","affected":["torch@<= 2.7.1 (fixed: 2.8.0)"],"epssScore":0.00331},{"id":"f9e48a1c-ab72-4298-8931-f40c9a45f1aa","url":"https://aisecwatch.com/issues/f9e48a1c-ab72-4298-8931-f40c9a45f1aa","cveId":"CVE-2025-3001","title":"CVE-2025-3001: A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function…","headline":"PyTorch memory corruption in torch.lstm_cell reachable locally","severity":"medium","publishedAt":"2025-03-31T20:15:27.277Z","affected":["torch@< 2.10.0 (fixed: 2.10.0)"],"epssScore":0.00198},{"id":"bc1f5b58-ad29-4c34-865e-5523d853e1ef","url":"https://aisecwatch.com/issues/bc1f5b58-ad29-4c34-865e-5523d853e1ef","cveId":"CVE-2025-3000","title":"CVE-2025-3000: A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The…","headline":"PyTorch memory corruption in torch.jit.script reachable from the local host","severity":"medium","publishedAt":"2025-03-31T19:15:46.297Z","affected":["torch@<= 2.12.1 (fixed: 2.13.0)"],"epssScore":0.00199},{"id":"e667a4a1-0085-403e-91bb-5b9138aabce9","url":"https://aisecwatch.com/issues/e667a4a1-0085-403e-91bb-5b9138aabce9","cveId":"CVE-2025-2999","title":"CVE-2025-2999: A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function…","headline":"PyTorch memory corruption in torch.nn.utils.rnn.unpack_sequence","severity":"medium","publishedAt":"2025-03-31T19:15:44.657Z","affected":["torch@< 2.9.1 (fixed: 2.9.1)"],"epssScore":0.00198},{"id":"c0abb025-c494-4a14-a53d-eabfba7affae","url":"https://aisecwatch.com/issues/c0abb025-c494-4a14-a53d-eabfba7affae","cveId":"CVE-2025-2998","title":"CVE-2025-2998: A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the…","headline":"PyTorch memory corruption in pad_packed_sequence via local access","severity":"medium","publishedAt":"2025-03-31T18:15:20.370Z","affected":["torch@<= 2.6.0"],"epssScore":0.00198},{"id":"1f306eba-acd9-4ed1-a02e-08889059eb06","url":"https://aisecwatch.com/issues/1f306eba-acd9-4ed1-a02e-08889059eb06","cveId":"CVE-2025-2953","title":"CVE-2025-2953: A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is…","headline":"PyTorch denial of service in torch.mkldnn_max_pool2d function","severity":"low","publishedAt":"2025-03-30T20:15:14.380Z","affected":["torch@< 2.7.1-rc1 (fixed: 2.7.1-rc1)"],"epssScore":0.00256},{"id":"db71261c-fd80-4e51-8d20-dac1891da505","url":"https://aisecwatch.com/issues/db71261c-fd80-4e51-8d20-dac1891da505","cveId":"CVE-2025-2149","title":"CVE-2025-2149: A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the…","headline":"PyTorch improper initialization in quantized Sigmoid module","severity":"low","publishedAt":"2025-03-10T17:15:36.290Z","affected":["torch@<= 2.6.0"],"epssScore":0.00257},{"id":"f792b627-4a8b-4aba-8f38-8977ac28ae8c","url":"https://aisecwatch.com/issues/f792b627-4a8b-4aba-8f38-8977ac28ae8c","cveId":"CVE-2025-2148","title":"CVE-2025-2148: A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is…","headline":"PyTorch memory corruption in torch.ops.profiler._call_end_callbacks_on_jit_fut","severity":"medium","publishedAt":"2025-03-10T16:15:12.617Z","affected":["torch@<= 2.6.0"],"epssScore":0.00437},{"id":"e61dab1a-a7e0-4a8b-aa7d-73eac1f8e8ab","url":"https://aisecwatch.com/issues/e61dab1a-a7e0-4a8b-aa7d-73eac1f8e8ab","cveId":"CVE-2024-31583","title":"CVE-2024-31583: Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in…","headline":"Pytorch use-after-free vulnerability in mobile interpreter","severity":"high","publishedAt":"2024-04-17T23:15:07.950Z","affected":["torch@< 2.2.0 (fixed: 2.2.0)"],"epssScore":0.00268},{"id":"30550ee0-b05a-4a31-bc2d-09a25896d086","url":"https://aisecwatch.com/issues/30550ee0-b05a-4a31-bc2d-09a25896d086","cveId":"CVE-2024-31580","title":"CVE-2024-31580: PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component…","headline":"PyTorch heap buffer overflow in vararg functions causes denial of service","severity":"medium","publishedAt":"2024-04-17T23:15:07.783Z","affected":["torch@< 2.2.0 (fixed: 2.2.0)"],"epssScore":0.00225},{"id":"fca25586-7cfa-4066-a551-bb9359d7287d","url":"https://aisecwatch.com/issues/fca25586-7cfa-4066-a551-bb9359d7287d","cveId":"CVE-2022-45907","title":"CVE-2022-45907: In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is…","headline":"PyTorch arbitrary code execution through parse_type_line type annotation parsing","severity":"critical","publishedAt":"2022-11-26T07:15:10.253Z","affected":["torch@<= 1.13.0 (fixed: 1.13.1)"],"epssScore":0.0129}],"checkedAt":"2026-10-09T21:49:30.337Z"},"meta":{"advisoryMatching":"by package name; advisory records do not state an ecosystem"}}