CVE-2024-27319

MEDIUM4.4EPSS 0.09%

Onnx Out-of-bounds Read vulnerability

Published: 2/23/2024Modified: 2/4/2026

Description

Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.

Affected packages (2)

  • PyPI/onnxfrom 0, < 1.16.0
  • PyPI/onnxfrom 0, < 08a399ba75a805b7813ab8936b91d0e274b08287, < 08a399ba75a805b7813ab8936b91d0e274b08287 | from 0, < 1.16.0

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.4CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

References (8)