{"schema_version":1,"title":"torch (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 31 vulnerabilities in torch (PyPI): 0 in the last 7 days and 1 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-3730, was published on 7 July 2026.","url":"https://junglewise.ai/threats/technologies/torch","json_url":"https://junglewise.ai/threats/technologies/torch.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/torch","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":31,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":1,"last_365_days":4},"latest":[{"cve":"CVE-2025-3730","cvss":3.1,"epss":0.0033,"slug":"cve-2025-3730-pytorch-improper-resource-shutdown-or-release-vulnerability","title":"PYSEC-2026-1970 - PyTorch Improper Resource Shutdown or Release vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:51.04064+00:00","url":"https://junglewise.ai/threats/cve-2025-3730-pytorch-improper-resource-shutdown-or-release-vulnerability"},{"cve":"CVE-2026-4538","cvss":3.1,"epss":0.004,"slug":"cve-2026-4538-pysec-2026-139-a-vulnerability-was-identified-in-pytorch-2-10-0","title":"PYSEC-2026-139 - A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The mani","severity":"low","exploited":false,"published_at":"2026-03-22T05:16:20.273+00:00","url":"https://junglewise.ai/threats/cve-2026-4538-pysec-2026-139-a-vulnerability-was-identified-in-pytorch-2-10-0"},{"cve":"CVE-2026-24747","cvss":8.8,"epss":0.0081,"slug":"cve-2026-24747-pytorch-arbitrary-code-execution-in-weights-only-unpickler","title":"PyTorch arbitrary code execution in weights_only unpickler","severity":"high","exploited":false,"published_at":"2026-01-27T22:15:56.47+00:00","url":"https://junglewise.ai/threats/cve-2026-24747-pytorch-arbitrary-code-execution-in-weights-only-unpickler"},{"cve":"CVE-2025-63396","cvss":3.3,"epss":0.0012,"slug":"cve-2025-63396-pytorch-denial-of-service-in-torch-profiler-profile","title":"PyTorch denial of service in torch.profiler.profile","severity":"low","exploited":false,"published_at":"2025-11-12T21:15:52.397+00:00","url":"https://junglewise.ai/threats/cve-2025-63396-pytorch-denial-of-service-in-torch-profiler-profile"},{"cve":"CVE-2025-55560","cvss":3.1,"epss":0.0041,"slug":"cve-2025-55560-pysec-2025-209-an-issue-in-pytorch-v2-7-0-can-lead-to-a-denial-of","title":"PYSEC-2025-209 - An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.","severity":"low","exploited":false,"published_at":"2025-09-25T16:15:35.197+00:00","url":"https://junglewise.ai/threats/cve-2025-55560-pysec-2025-209-an-issue-in-pytorch-v2-7-0-can-lead-to-a-denial-of"},{"cve":"CVE-2025-55558","cvss":3.1,"epss":0.0045,"slug":"cve-2025-55558-pysec-2025-208-a-buffer-overflow-occurs-in-pytorch-v2-7-0-when-a","title":"PYSEC-2025-208 - A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tenso","severity":"low","exploited":false,"published_at":"2025-09-25T16:15:34.96+00:00","url":"https://junglewise.ai/threats/cve-2025-55558-pysec-2025-208-a-buffer-overflow-occurs-in-pytorch-v2-7-0-when-a"},{"cve":"CVE-2025-55557","cvss":3.1,"epss":0.0041,"slug":"cve-2025-55557-pysec-2025-207-a-name-error-occurs-in-pytorch-v2-7-0-when-a","title":"PYSEC-2025-207 - A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Serv","severity":"low","exploited":false,"published_at":"2025-09-25T16:15:34.833+00:00","url":"https://junglewise.ai/threats/cve-2025-55557-pysec-2025-207-a-name-error-occurs-in-pytorch-v2-7-0-when-a"},{"cve":"CVE-2025-55554","cvss":3.1,"epss":0.0032,"slug":"cve-2025-55554-pysec-2025-206-pytorch-v2-8-0-was-discovered-to-contain-an","title":"PYSEC-2025-206 - pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().","severity":"low","exploited":false,"published_at":"2025-09-25T16:15:34.593+00:00","url":"https://junglewise.ai/threats/cve-2025-55554-pysec-2025-206-pytorch-v2-8-0-was-discovered-to-contain-an"},{"cve":"CVE-2025-55553","cvss":3.1,"epss":0.0041,"slug":"cve-2025-55553-pysec-2025-205-a-syntax-error-in-the-component-proxy-tensor-py-of","title":"PYSEC-2025-205 - A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).","severity":"low","exploited":false,"published_at":"2025-09-25T16:15:34.46+00:00","url":"https://junglewise.ai/threats/cve-2025-55553-pysec-2025-205-a-syntax-error-in-the-component-proxy-tensor-py-of"},{"cve":"CVE-2025-55552","cvss":3.1,"epss":0.0042,"slug":"cve-2025-55552-pysec-2025-204-pytorch-v2-8-0-was-discovered-to-display","title":"PYSEC-2025-204 - pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.","severity":"low","exploited":false,"published_at":"2025-09-25T16:15:34.32+00:00","url":"https://junglewise.ai/threats/cve-2025-55552-pysec-2025-204-pytorch-v2-8-0-was-discovered-to-display"},{"cve":"CVE-2025-55551","cvss":3.1,"epss":0.0042,"slug":"cve-2025-55551-pysec-2025-203-an-issue-in-the-component-torch-linalg-lu-of","title":"PYSEC-2025-203 - An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice oper","severity":"low","exploited":false,"published_at":"2025-09-25T15:16:12.887+00:00","url":"https://junglewise.ai/threats/cve-2025-55551-pysec-2025-203-an-issue-in-the-component-torch-linalg-lu-of"},{"cve":"CVE-2025-46153","cvss":3.1,"epss":0.0042,"slug":"cve-2025-46153-pysec-2025-202-pytorch-before-3-7-0-has-a-bernoulli-p-decompose","title":"PYSEC-2025-202 - PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU impl","severity":"low","exploited":false,"published_at":"2025-09-25T15:16:12.603+00:00","url":"https://junglewise.ai/threats/cve-2025-46153-pysec-2025-202-pytorch-before-3-7-0-has-a-bernoulli-p-decompose"},{"cve":"CVE-2025-46152","cvss":3.1,"epss":0.0045,"slug":"cve-2025-46152-pysec-2025-201-in-pytorch-before-2-7-0-bitwise-right-shift","title":"PYSEC-2025-201 - In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the \"other\" argument.","severity":"low","exploited":false,"published_at":"2025-09-25T15:16:12.47+00:00","url":"https://junglewise.ai/threats/cve-2025-46152-pysec-2025-201-in-pytorch-before-2-7-0-bitwise-right-shift"},{"cve":"CVE-2025-46150","cvss":3.1,"epss":0.0039,"slug":"cve-2025-46150-pysec-2025-200-in-pytorch-before-2-7-0-when-torch-compile-is-used","title":"PYSEC-2025-200 - In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.","severity":"low","exploited":false,"published_at":"2025-09-25T15:16:12.303+00:00","url":"https://junglewise.ai/threats/cve-2025-46150-pysec-2025-200-in-pytorch-before-2-7-0-when-torch-compile-is-used"},{"cve":"CVE-2025-46149","cvss":3.1,"epss":0.0036,"slug":"cve-2025-46149-pysec-2025-199-in-pytorch-before-2-7-0-when-inductor-is-used-nn","title":"PYSEC-2025-199 - In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.","severity":"low","exploited":false,"published_at":"2025-09-25T15:16:12.153+00:00","url":"https://junglewise.ai/threats/cve-2025-46149-pysec-2025-199-in-pytorch-before-2-7-0-when-inductor-is-used-nn"},{"cve":"CVE-2025-46148","cvss":3.1,"epss":0.004,"slug":"cve-2025-46148-pysec-2025-198-in-pytorch-through-2-6-0-when-eager-is-used-nn","title":"PYSEC-2025-198 - In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.","severity":"low","exploited":false,"published_at":"2025-09-25T15:16:12.007+00:00","url":"https://junglewise.ai/threats/cve-2025-46148-pysec-2025-198-in-pytorch-through-2-6-0-when-eager-is-used-nn"},{"cve":"CVE-2025-32434","cvss":4,"epss":0.0219,"slug":"cve-2025-32434-pytorch-torch-load-with-weights-only-true-leads-to-remote-code","title":"PYSEC-2025-41 - PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based aut","severity":"medium","exploited":false,"published_at":"2025-04-18T16:15:23+00:00","url":"https://junglewise.ai/threats/cve-2025-32434-pytorch-torch-load-with-weights-only-true-leads-to-remote-code"},{"cve":"CVE-2025-3136","cvss":4,"epss":0.0026,"slug":"cve-2025-3136-pysec-2025-197-a-vulnerability-which-was-classified-as-problematic","title":"PYSEC-2025-197 - A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.cac","severity":"medium","exploited":false,"published_at":"2025-04-03T04:15:38.54+00:00","url":"https://junglewise.ai/threats/cve-2025-3136-pysec-2025-197-a-vulnerability-which-was-classified-as-problematic"},{"cve":"CVE-2025-3121","cvss":3.1,"epss":0.0027,"slug":"cve-2025-3121-pysec-2025-196-a-vulnerability-classified-as-problematic-has-been","title":"PYSEC-2025-196 - A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. Th","severity":"low","exploited":false,"published_at":"2025-04-02T22:15:21.22+00:00","url":"https://junglewise.ai/threats/cve-2025-3121-pysec-2025-196-a-vulnerability-classified-as-problematic-has-been"},{"cve":"CVE-2025-3001","cvss":5.3,"epss":0.002,"slug":"cve-2025-3001-pytorch-memory-corruption-in-torch-lstm-cell","title":"PyTorch memory corruption in torch.lstm_cell","severity":"medium","exploited":false,"published_at":"2025-03-31T18:31:08+00:00","url":"https://junglewise.ai/threats/cve-2025-3001-pytorch-memory-corruption-in-torch-lstm-cell"},{"cve":"CVE-2025-3000","cvss":5.3,"epss":0.002,"slug":"cve-2025-3000-pytorch-memory-corruption-in-torch-jit-script","title":"PyTorch memory corruption in torch.jit.script","severity":"medium","exploited":false,"published_at":"2025-03-31T15:30:48+00:00","url":"https://junglewise.ai/threats/cve-2025-3000-pytorch-memory-corruption-in-torch-jit-script"},{"cve":"CVE-2025-2998","cvss":5.3,"epss":0.002,"slug":"cve-2025-2998-pytorch-memory-corruption-in-pad-packed-sequence","title":"PyTorch memory corruption in pad_packed_sequence","severity":"medium","exploited":false,"published_at":"2025-03-31T15:30:48+00:00","url":"https://junglewise.ai/threats/cve-2025-2998-pytorch-memory-corruption-in-pad-packed-sequence"},{"cve":"CVE-2025-2999","cvss":5.3,"epss":0.002,"slug":"cve-2025-2999-pytorch-memory-corruption-in-unpack-sequence-and-pad-packed","title":"PyTorch memory corruption in unpack_sequence and pad_packed_sequence","severity":"medium","exploited":false,"published_at":"2025-03-31T15:30:48+00:00","url":"https://junglewise.ai/threats/cve-2025-2999-pytorch-memory-corruption-in-unpack-sequence-and-pad-packed"},{"cve":"CVE-2025-2953","cvss":3.3,"epss":0.0026,"slug":"cve-2025-2953-pytorch-denial-of-service-in-torch-mkldnn-max-pool2d","title":"PyTorch denial of service in torch.mkldnn_max_pool2d","severity":"low","exploited":false,"published_at":"2025-03-30T18:30:24+00:00","url":"https://junglewise.ai/threats/cve-2025-2953-pytorch-denial-of-service-in-torch-mkldnn-max-pool2d"},{"cve":"CVE-2025-2149","cvss":4,"epss":0.0025,"slug":"cve-2025-2149-pytorch-improper-initialization-in-quantized-sigmoid-module","title":"PyTorch improper initialization in Quantized Sigmoid Module","severity":"medium","exploited":false,"published_at":"2025-03-10T15:30:47+00:00","url":"https://junglewise.ai/threats/cve-2025-2149-pytorch-improper-initialization-in-quantized-sigmoid-module"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"torch (PyPI)","slug":"torch","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://pytorch.org/","repo_url":"https://github.com/pytorch/pytorch","description":"An open-source machine learning framework that provides a wide range of algorithms and tools for deep learning.","url":"https://junglewise.ai/threats/technologies/torch"},"most_severe":[{"cve":"CVE-2026-24747","cvss":8.8,"epss":0.0081,"slug":"cve-2026-24747-pytorch-arbitrary-code-execution-in-weights-only-unpickler","title":"PyTorch arbitrary code execution in weights_only unpickler","severity":"high","exploited":false,"published_at":"2026-01-27T22:15:56.47+00:00","url":"https://junglewise.ai/threats/cve-2026-24747-pytorch-arbitrary-code-execution-in-weights-only-unpickler"},{"cve":"CVE-2025-3001","cvss":5.3,"epss":0.002,"slug":"cve-2025-3001-pytorch-memory-corruption-in-torch-lstm-cell","title":"PyTorch memory corruption in torch.lstm_cell","severity":"medium","exploited":false,"published_at":"2025-03-31T18:31:08+00:00","url":"https://junglewise.ai/threats/cve-2025-3001-pytorch-memory-corruption-in-torch-lstm-cell"},{"cve":"CVE-2025-2999","cvss":5.3,"epss":0.002,"slug":"cve-2025-2999-pytorch-memory-corruption-in-unpack-sequence-and-pad-packed","title":"PyTorch memory corruption in unpack_sequence and pad_packed_sequence","severity":"medium","exploited":false,"published_at":"2025-03-31T15:30:48+00:00","url":"https://junglewise.ai/threats/cve-2025-2999-pytorch-memory-corruption-in-unpack-sequence-and-pad-packed"},{"cve":"CVE-2025-2998","cvss":5.3,"epss":0.002,"slug":"cve-2025-2998-pytorch-memory-corruption-in-pad-packed-sequence","title":"PyTorch memory corruption in pad_packed_sequence","severity":"medium","exploited":false,"published_at":"2025-03-31T15:30:48+00:00","url":"https://junglewise.ai/threats/cve-2025-2998-pytorch-memory-corruption-in-pad-packed-sequence"},{"cve":"CVE-2025-3000","cvss":5.3,"epss":0.002,"slug":"cve-2025-3000-pytorch-memory-corruption-in-torch-jit-script","title":"PyTorch memory corruption in torch.jit.script","severity":"medium","exploited":false,"published_at":"2025-03-31T15:30:48+00:00","url":"https://junglewise.ai/threats/cve-2025-3000-pytorch-memory-corruption-in-torch-jit-script"},{"cve":"CVE-2025-2148","cvss":5,"epss":0.0043,"slug":"cve-2025-2148-pytorch-memory-corruption-in-profiler-tuple-handler","title":"PyTorch memory corruption in profiler Tuple Handler","severity":"medium","exploited":false,"published_at":"2025-03-10T12:30:55+00:00","url":"https://junglewise.ai/threats/cve-2025-2148-pytorch-memory-corruption-in-profiler-tuple-handler"},{"cve":"CVE-2025-32434","cvss":4,"epss":0.0219,"slug":"cve-2025-32434-pytorch-torch-load-with-weights-only-true-leads-to-remote-code","title":"PYSEC-2025-41 - PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based aut","severity":"medium","exploited":false,"published_at":"2025-04-18T16:15:23+00:00","url":"https://junglewise.ai/threats/cve-2025-32434-pytorch-torch-load-with-weights-only-true-leads-to-remote-code"},{"cve":"CVE-2025-3136","cvss":4,"epss":0.0026,"slug":"cve-2025-3136-pysec-2025-197-a-vulnerability-which-was-classified-as-problematic","title":"PYSEC-2025-197 - A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.cac","severity":"medium","exploited":false,"published_at":"2025-04-03T04:15:38.54+00:00","url":"https://junglewise.ai/threats/cve-2025-3136-pysec-2025-197-a-vulnerability-which-was-classified-as-problematic"},{"cve":"CVE-2025-2149","cvss":4,"epss":0.0025,"slug":"cve-2025-2149-pytorch-improper-initialization-in-quantized-sigmoid-module","title":"PyTorch improper initialization in Quantized Sigmoid Module","severity":"medium","exploited":false,"published_at":"2025-03-10T15:30:47+00:00","url":"https://junglewise.ai/threats/cve-2025-2149-pytorch-improper-initialization-in-quantized-sigmoid-module"},{"cve":"CVE-2025-2953","cvss":3.3,"epss":0.0026,"slug":"cve-2025-2953-pytorch-denial-of-service-in-torch-mkldnn-max-pool2d","title":"PyTorch denial of service in torch.mkldnn_max_pool2d","severity":"low","exploited":false,"published_at":"2025-03-30T18:30:24+00:00","url":"https://junglewise.ai/threats/cve-2025-2953-pytorch-denial-of-service-in-torch-mkldnn-max-pool2d"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}