CVE-2026-44512 is a denial of service vulnerability in Open Neural Network Exchange (ONNX) versions from 1.9.0 before 1.22.0. The issue is caused by a null pointer dereference in the Upsample_6_7::adapt_upsample_6_7() function when processing an untrusted model with an Upsample node that has zero inputs. This vulnerability can lead to an unrecoverable denial of service. Users of affected versions should a [truncated]
A vulnerability has been found in onnx onnx-mlir up to 0.5.0.0. Affected by this issue is the function generate_hash_key of the file src/Runtime/python/torch_onnxmlir/src/torch_onnxmlir/backend.py of the component Placeholder Node Cache Handler. Such manipulation leads to use of weak hash. An attack has to be approached locally. A high complexity level is associated with this attack. The exploitation is k [truncated]
CVE-2026-27489 is a high-severity vulnerability in Open Neural Network Exchange (ONNX), a standard for machine learning interoperability. Prior to version 1.21.0, ONNX was susceptible to a path traversal vulnerability via symlink, allowing attackers to read arbitrary files outside the model or user-provided directory. This issue has been patched in version 1.21.0. The vulnerability has a CVSS score of 8.7 [truncated]
CVE-2026-28500 is a high-severity vulnerability (CVSS Score: 8.6) affecting Open Neural Network Exchange (ONNX), an open standard for machine learning interoperability. The vulnerability exists in the onnx.hub.load() function, which is used to load machine learning models. Due to improper logic in the repository trust verification mechanism, an attacker can bypass security controls and silently exfiltrate [truncated]