{"schema_version":1,"title":"paddlepaddle (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 32 vulnerabilities in paddlepaddle (PyPI): 0 in the last 7 days and 8 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2024-1603, was published on 7 July 2026.","url":"https://junglewise.ai/threats/technologies/paddlepaddle","json_url":"https://junglewise.ai/threats/technologies/paddlepaddle.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/paddlepaddle","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":32,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":8,"last_365_days":8},"latest":[{"cve":"CVE-2024-1603","cvss":3.1,"epss":0.0056,"slug":"cve-2024-1603-paddlepaddle-allows-arbitrary-file-read-via-paddle-vision-ops-read","title":"PYSEC-2026-1755 - PaddlePaddle allows arbitrary file read via paddle.vision.ops.read_file","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:36.342486+00:00","url":"https://junglewise.ai/threats/cve-2024-1603-paddlepaddle-allows-arbitrary-file-read-via-paddle-vision-ops-read"},{"cve":"CVE-2024-0815","cvss":3.1,"epss":0.0113,"slug":"cve-2024-0815-paddlepaddle-command-injection-in-paddle-utils-download-wget","title":"PYSEC-2026-1756 - PaddlePaddle command injection in paddle.utils.download._wget_download","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:34.575359+00:00","url":"https://junglewise.ai/threats/cve-2024-0815-paddlepaddle-command-injection-in-paddle-utils-download-wget"},{"cve":"CVE-2024-0817","cvss":3.1,"epss":0.0117,"slug":"cve-2024-0817-paddlepaddle-command-injection-vulnerability","title":"PYSEC-2026-1754 - PaddlePaddle command injection vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:34.489529+00:00","url":"https://junglewise.ai/threats/cve-2024-0817-paddlepaddle-command-injection-vulnerability"},{"cve":"CVE-2024-0521","cvss":3,"epss":0.0046,"slug":"cve-2024-0521-code-injection-in-paddlepaddle","title":"PYSEC-2026-444 - Code Injection in paddlepaddle","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:41.52371+00:00","url":"https://junglewise.ai/threats/cve-2024-0521-code-injection-in-paddlepaddle"},{"cve":"CVE-2024-0818","cvss":3.1,"epss":0.0106,"slug":"cve-2024-0818-paddlepaddle-arbitrary-file-overwrite-via-path-traversal","title":"PYSEC-2026-442 - PaddlePaddle Path Traversal vulnerability","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:39.144118+00:00","url":"https://junglewise.ai/threats/cve-2024-0818-paddlepaddle-arbitrary-file-overwrite-via-path-traversal"},{"cve":"CVE-2024-0917","cvss":3.1,"epss":0.0165,"slug":"cve-2024-0917-paddlepaddle-vulnerable-to-remote-code-execution","title":"PYSEC-2026-445 - PaddlePaddle vulnerable to remote code execution","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:39.027739+00:00","url":"https://junglewise.ai/threats/cve-2024-0917-paddlepaddle-vulnerable-to-remote-code-execution"},{"cve":"CVE-2022-46741","cvss":3.1,"epss":0.0068,"slug":"cve-2022-46741-paddlepaddle-out-of-bounds-read-in-gather-tree","title":"PYSEC-2026-441 - PaddlePaddle Out-of-bounds Read vulnerability","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:34.05102+00:00","url":"https://junglewise.ai/threats/cve-2022-46741-paddlepaddle-out-of-bounds-read-in-gather-tree"},{"cve":"CVE-2022-45908","cvss":3.1,"epss":0.0135,"slug":"cve-2022-45908-paddlepaddle-vulnerable-to-code-injection-via-winstr","title":"PYSEC-2026-443 - PaddlePaddle vulnerable to code injection via winstr","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:33.104936+00:00","url":"https://junglewise.ai/threats/cve-2022-45908-paddlepaddle-vulnerable-to-code-injection-via-winstr"},{"cve":"CVE-2023-52302","cvss":3.1,"epss":0.0055,"slug":"cve-2023-52302-paddlepaddle-null-pointer-dereference-in-paddle-nextafter","title":"PYSEC-2024-134 - Nullptr in paddle.nextafter in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-52302-paddlepaddle-null-pointer-dereference-in-paddle-nextafter"},{"cve":"CVE-2023-52310","cvss":3.1,"epss":0.0118,"slug":"cve-2023-52310-paddlepaddle-command-injection-in-get-online-pass-interval","title":"PYSEC-2024-142 - PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-52310-paddlepaddle-command-injection-in-get-online-pass-interval"},{"cve":"CVE-2023-52305","cvss":3.1,"epss":0.0049,"slug":"cve-2023-52305-paddlepaddle-floating-point-exception-in-paddle-topk","title":"PYSEC-2024-137 - FPE in paddle.topk in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-52305-paddlepaddle-floating-point-exception-in-paddle-topk"},{"cve":"CVE-2023-52303","cvss":3.1,"epss":0.0049,"slug":"cve-2023-52303-paddlepaddle-null-pointer-dereference-in-paddle-put-along-axis","title":"PYSEC-2024-135 - Nullptr in paddle.put_along_axis in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-52303-paddlepaddle-null-pointer-dereference-in-paddle-put-along-axis"},{"cve":"CVE-2023-38674","cvss":3.1,"epss":0.0049,"slug":"cve-2023-38674-paddlepaddle-floating-point-exception-in-paddle-nanmedian","title":"PYSEC-2024-129 - FPE in paddle.nanmedian in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-38674-paddlepaddle-floating-point-exception-in-paddle-nanmedian"},{"cve":"CVE-2023-52311","cvss":3.1,"epss":0.0118,"slug":"cve-2023-52311-paddlepaddle-command-injection-in-wget-download","title":"PYSEC-2024-143 - PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary commands on the opera","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-52311-paddlepaddle-command-injection-in-wget-download"},{"cve":"CVE-2023-52309","cvss":3.1,"epss":0.0054,"slug":"cve-2023-52309-paddlepaddle-heap-buffer-overflow-in-paddle-repeat-interleave","title":"PYSEC-2024-141 - Heap buffer overflow in paddle.repeat_interleave in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, information disclo","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-52309-paddlepaddle-heap-buffer-overflow-in-paddle-repeat-interleave"},{"cve":"CVE-2023-52308","cvss":3.1,"epss":0.0049,"slug":"cve-2023-52308-paddlepaddle-floating-point-exception-in-paddle-amin","title":"PYSEC-2024-140 - FPE in paddle.amin in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-52308-paddlepaddle-floating-point-exception-in-paddle-amin"},{"cve":"CVE-2023-38677","cvss":3.1,"epss":0.0049,"slug":"cve-2023-38677-paddlepaddle-floating-point-exception-in-paddle-linalg-eig","title":"PYSEC-2024-132 - FPE in paddle.linalg.eig in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-38677-paddlepaddle-floating-point-exception-in-paddle-linalg-eig"},{"cve":"CVE-2023-38676","cvss":3.1,"epss":0.0049,"slug":"cve-2023-38676-paddlepaddle-segfault-in-paddle-dot","title":"PYSEC-2024-131 - Nullptr in paddle.dot in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-38676-paddlepaddle-segfault-in-paddle-dot"},{"cve":"CVE-2023-52304","cvss":3.1,"epss":0.0058,"slug":"cve-2023-52304-paddlepaddle-stack-overflow-in-paddle-searchsorted","title":"PYSEC-2024-136 - Stack overflow in paddle.searchsorted in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-52304-paddlepaddle-stack-overflow-in-paddle-searchsorted"},{"cve":"CVE-2023-38675","cvss":3.1,"epss":0.0049,"slug":"cve-2023-38675-paddlepaddle-floating-point-exception-in-paddle-linalg-matrix","title":"PYSEC-2024-130 - FPE in paddle.linalg.matrix_rank in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-38675-paddlepaddle-floating-point-exception-in-paddle-linalg-matrix"},{"cve":"CVE-2023-52306","cvss":3.1,"epss":0.0049,"slug":"cve-2023-52306-paddlepaddle-floating-point-exception-in-paddle-lerp","title":"PYSEC-2024-138 - FPE in paddle.lerp in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-52306-paddlepaddle-floating-point-exception-in-paddle-lerp"},{"cve":"CVE-2023-52313","cvss":3.1,"epss":0.0049,"slug":"cve-2023-52313-paddlepaddle-floating-point-exception-in-argmin-and-argmax","title":"PYSEC-2024-145 - FPE in paddle.argmin and paddle.argmax in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-52313-paddlepaddle-floating-point-exception-in-argmin-and-argmax"},{"cve":"CVE-2023-52307","cvss":3.1,"epss":0.0053,"slug":"cve-2023-52307-paddlepaddle-stack-overflow-in-paddle-linalg-lu-unpack","title":"PYSEC-2024-139 - Stack overflow in paddle.linalg.lu_unpack in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-52307-paddlepaddle-stack-overflow-in-paddle-linalg-lu-unpack"},{"cve":"CVE-2023-52314","cvss":3.1,"epss":0.0118,"slug":"cve-2023-52314-paddlepaddle-command-injection-in-convert-shape-compare","title":"PYSEC-2024-146 - PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbitrary commands on th","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-52314-paddlepaddle-command-injection-in-convert-shape-compare"},{"cve":"CVE-2023-52312","cvss":3.1,"epss":0.0049,"slug":"cve-2023-52312-paddlepaddle-nullptr-dereference-in-paddle-crop","title":"PYSEC-2024-144 - Nullptr dereference in paddle.crop in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-52312-paddlepaddle-nullptr-dereference-in-paddle-crop"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"paddlepaddle (PyPI)","slug":"paddlepaddle","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/paddlepaddle"},"most_severe":[{"cve":"CVE-2023-38673","cvss":3.1,"epss":0.0234,"slug":"cve-2023-38673-command-injection-in-paddlepaddle","title":"PYSEC-2023-126 - PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating syst","severity":"low","exploited":false,"published_at":"2023-07-26T12:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-38673-command-injection-in-paddlepaddle"},{"cve":"CVE-2024-0917","cvss":3.1,"epss":0.0165,"slug":"cve-2024-0917-paddlepaddle-vulnerable-to-remote-code-execution","title":"PYSEC-2026-445 - PaddlePaddle vulnerable to remote code execution","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:39.027739+00:00","url":"https://junglewise.ai/threats/cve-2024-0917-paddlepaddle-vulnerable-to-remote-code-execution"},{"cve":"CVE-2022-45908","cvss":3.1,"epss":0.0135,"slug":"cve-2022-45908-paddlepaddle-vulnerable-to-code-injection-via-winstr","title":"PYSEC-2026-443 - PaddlePaddle vulnerable to code injection via winstr","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:33.104936+00:00","url":"https://junglewise.ai/threats/cve-2022-45908-paddlepaddle-vulnerable-to-code-injection-via-winstr"},{"cve":"CVE-2023-52314","cvss":3.1,"epss":0.0118,"slug":"cve-2023-52314-paddlepaddle-command-injection-in-convert-shape-compare","title":"PYSEC-2024-146 - PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbitrary commands on th","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-52314-paddlepaddle-command-injection-in-convert-shape-compare"},{"cve":"CVE-2023-52310","cvss":3.1,"epss":0.0118,"slug":"cve-2023-52310-paddlepaddle-command-injection-in-get-online-pass-interval","title":"PYSEC-2024-142 - PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-52310-paddlepaddle-command-injection-in-get-online-pass-interval"},{"cve":"CVE-2023-52311","cvss":3.1,"epss":0.0118,"slug":"cve-2023-52311-paddlepaddle-command-injection-in-wget-download","title":"PYSEC-2024-143 - PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary commands on the opera","severity":"low","exploited":false,"published_at":"2024-01-03T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-52311-paddlepaddle-command-injection-in-wget-download"},{"cve":"CVE-2024-0817","cvss":3.1,"epss":0.0117,"slug":"cve-2024-0817-paddlepaddle-command-injection-vulnerability","title":"PYSEC-2026-1754 - PaddlePaddle command injection vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:34.489529+00:00","url":"https://junglewise.ai/threats/cve-2024-0817-paddlepaddle-command-injection-vulnerability"},{"cve":"CVE-2022-46742","cvss":3.1,"epss":0.0114,"slug":"cve-2022-46742-paddlepaddle-vulnerable-to-code-injection","title":"PYSEC-2022-43063 - Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution.","severity":"low","exploited":false,"published_at":"2022-12-07T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-46742-paddlepaddle-vulnerable-to-code-injection"},{"cve":"CVE-2024-0815","cvss":3.1,"epss":0.0113,"slug":"cve-2024-0815-paddlepaddle-command-injection-in-paddle-utils-download-wget","title":"PYSEC-2026-1756 - PaddlePaddle command injection in paddle.utils.download._wget_download","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:34.575359+00:00","url":"https://junglewise.ai/threats/cve-2024-0815-paddlepaddle-command-injection-in-paddle-utils-download-wget"},{"cve":"CVE-2024-0818","cvss":3.1,"epss":0.0106,"slug":"cve-2024-0818-paddlepaddle-arbitrary-file-overwrite-via-path-traversal","title":"PYSEC-2026-442 - PaddlePaddle Path Traversal vulnerability","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:39.144118+00:00","url":"https://junglewise.ai/threats/cve-2024-0818-paddlepaddle-arbitrary-file-overwrite-via-path-traversal"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}