CVE-2026-63632: Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0,
lowvulnerability
security
Summary
ONNX (Open Neural Network Exchange, a standard format for sharing machine learning models) versions 1.3.0 through 1.22.0 have a bug where converting models to an older format can crash if certain input data doesn't have enough dimensions, because the code tries to read array positions that don't exist without checking first.
Solution / Mitigation
This issue is fixed in version 1.22.0.
Vulnerability Details
CVSS Score
3.3(low)
EPSS (30-day exploit probability)
EPSS: 0.0%
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Attack Vector
local
Attack Complexity
low
Privileges Required
none
User Interaction
required
Disclosure Date
August 18, 2026
Classification
Attack SophisticationModerate
Impact (CIA+S)
availability
AI Component TargetedFramework
Affected Vendors
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63632
First tracked: August 18, 2026 at 02:09 PM
Classified by LLM (prompt v3) · confidence: 85%