CVE-2026-34445

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the "keys" in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:linuxfoundation:onnx:*:*:*:*:*:*:*:*

History

15 Apr 2026, 15:08

Type Values Removed Values Added
CPE cpe:2.3:a:linuxfoundation:onnx:*:*:*:*:*:*:*:*
First Time Linuxfoundation
Linuxfoundation onnx
References () https://github.com/onnx/onnx/commit/e30c6935d67cc3eca2fa284e37248e7c0036c46b - () https://github.com/onnx/onnx/commit/e30c6935d67cc3eca2fa284e37248e7c0036c46b - Patch
References () https://github.com/onnx/onnx/pull/7751 - () https://github.com/onnx/onnx/pull/7751 - Issue Tracking, Patch
References () https://github.com/onnx/onnx/security/advisories/GHSA-538c-55jv-c5g9 - () https://github.com/onnx/onnx/security/advisories/GHSA-538c-55jv-c5g9 - Patch, Vendor Advisory

01 Apr 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-01 18:16

Updated : 2026-04-15 15:08


NVD link : CVE-2026-34445

Mitre link : CVE-2026-34445

CVE.ORG link : CVE-2026-34445


JSON object : View

Products Affected

linuxfoundation

  • onnx
CWE
CWE-20

Improper Input Validation

CWE-400

Uncontrolled Resource Consumption

CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes