CVE-2026-34445 is a high-severity vulnerability affecting the Open Neural Network Exchange (ONNX) framework prior to version 1.21.0. It allows an unauthenticated attacker to craft a malicious ONNX model that overwrites internal object properties due to improper validation of metadata loaded via Python's setattr() function. With a CVSS score of 8.6, this vulnerability has a network attack vector and low attack complexity, requiring no user interaction or privileges, potentially leading to high availability impact. While the CVE is listed as "Active" on the Hot List and has some community discussion, there is currently no public exploit code available on platforms like Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.21.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:onnx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.