Horovod is a distributed deep-learning framework that facilitates parallel training across multiple GPUs and nodes, with its vulnerability footprint concentrated in the core library. Observed weakness classes center on deserialization of untrusted data, resource exposure across trust boundaries, and insecure temporary file handling—issues characteristic of a framework that orchestrates communication and I/O across distributed compute environments. Current CVE counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Horovod over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-10190CRITICAL Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability is due to improper handling of base64-encoded data in the `E | Mar 20, 2025 | 9.8 | 26 | NO | NO |
CVE-2022-0315HIGH Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0. | Mar 24, 2022 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Horovod.
Media articles that mention a CVE ID that affects a product developed by Horovod — matched by CVE ID, not by vendor name.