PatchSiren cyber security CVE debrief
CVE-2026-11329 onnx CVE debrief
A vulnerability has been found in onnx onnx-mlir up to 0.5.0.0. Affected by this issue is the function generate_hash_key of the file src/Runtime/python/torch_onnxmlir/src/torch_onnxmlir/backend.py of the component Placeholder Node Cache Handler. Such manipulation leads to use of weak hash. An attack has to be approached locally. A high complexity level is associated with this attack. The exploitation is known to be difficult.
- Vendor
- onnx
- Product
- onnx-mlir
- CVSS
- LOW 2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-05
- Original CVE updated
- 2026-06-05
- Advisory published
- 2026-06-05
- Advisory updated
- 2026-06-05
Who should care
Users of onnx onnx-mlir up to 0.5.0.0
Technical summary
The vulnerability is caused by the use of a weak hash in the generate_hash_key function of the Placeholder Node Cache Handler. This can be exploited locally, but the complexity of the attack is high and the exploitation is difficult.
Defensive priority
LOW
Recommended defensive actions
- Apply the patch 72c5187ff6d13c2c2b3d3789b8f5faf99f08a5b4 to resolve this issue.
Evidence notes
The vulnerability has been rated as problematic with a CVSS score of 2 and a CVSS severity of LOW.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-11329 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-11329
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-11329 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-11329
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/onnx/onnx-mlir/
-
Source reference
Unverified legacy reference
URL: https://github.com/onnx/onnx-mlir/commit/72c5187ff6d13c2c2b3d3789b8f5faf99f08a5b4
-
Source reference
Unverified legacy reference
URL: https://github.com/onnx/onnx-mlir/pull/3427
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-11329
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/832358
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/368865
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/368865/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.