Junglewise Threat Intelligence

CVE-2025-65887: Oneflow-Inc OneFlow division by zero in flow.floor_divide

CVE-2025-65887 · Severity: medium · CVSS 6.5 · Published 2026-01-28

Technologies: Oneflow. Vendors: Oneflow.

Executive brief

OneFlow is an open-source deep learning framework used for building and deploying artificial intelligence models. A flaw in its mathematical processing component allows an attacker to crash the software by providing a specific type of invalid data. This results in a denial-of-service, potentially interrupting AI training or inference tasks and impacting service availability.

Technical details

A division-by-zero vulnerability (CWE-369) exists in the 'flow.floor_divide()' function of OneFlow version 0.9.0. The issue is triggered when the function receives a divisor tensor containing zero values, which leads to a floating-point exception and a subsequent core dump. An attacker can exploit this by providing specially crafted input tensors to an application utilizing this framework. This results in a complete crash of the process (Denial of Service). The vulnerability is reachable over the network if the application exposes an interface that processes user-supplied tensors.

Affected products

  • Oneflow-Inc OneFlow 0.9.0

Timeline

  • 2025-06-30: disclosed: Issue reported on GitHub repository
  • 2026-01-28: advisory: NVD publication date

References

Related threats