CVE-2025-65886 is a shape mismatch vulnerability in OneFlow v0.9.0 that allows unauthenticated attackers to cause a Denial of Service (DoS) by supplying crafted tensor shapes. This vulnerability has a CVSS score of 7.5 (HIGH) due to its network-based attack vector, low attack complexity, and high impact on availability. While no public exploit intelligence or active exploitation has been observed, its FAUCET Risk Score of 91/100 indicates a significant potential risk. Community discussion and media coverage for this CVE are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9.0CPE matchmatch criteria | cpe:2.3:a:oneflow:oneflow:0.9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.