CVE-2026-55093: Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1
Summary
Tract, a toolkit for running machine learning models (TensorFlow and ONNX inference, which means executing pre-trained AI models), has a vulnerability in how it handles tensor dimensions (the sizes of data arrays). Before versions 0.21.16, 0.22.2, and 0.23.1, an attacker could craft a malicious model file that tricks Tract into allocating a small amount of memory while actually trying to access a much larger area, potentially exposing nearby data in memory or crashing the program.
Solution / Mitigation
This issue is fixed in versions 0.21.16, 0.22.2, and 0.23.1.
Vulnerability Details
6.1(medium)
EPSS: 0.0%
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
local
low
none
required
September 14, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-55093
First tracked: September 14, 2026 at 08:07 PM
Classified by LLM (prompt v3) · confidence: 92%