Pytorch Lightning
Vendor:
First CVE: Dec 23, 2021 · Active for 4 years
9
Total CVEs
More Total CVEs than 86% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
8.8
Avg CVSS
Higher Avg CVSS than 79% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pytorch Lightning over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 23, 2021
4 years ago
Most Recent CVE
Jul 15, 2026
12 days ago
CVE Severity & Scoring
Pytorch Lightning9 CVEs
44%
56%
All CVEs352,785 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local3 (33.3%)
Network6 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (66.7%)
Unknown0 (0.0%)
Required3 (33.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5452CRITICAL A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement | Jun 6, 2024 | 9.8 | 44 | NO | NO |
CVE-2026-44484CRITICAL PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting me | May 14, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-58659HIGH PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled m | Jul 15, 2026 | 7.8 | 33 | NO | NO |
CVE-2024-5980CRITICAL A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp | Jun 27, 2024 | 9.8 | 30 | NO | NO |
CVE-2026-31221HIGH PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoi | May 12, 2026 | 7.8 | 27 | NO | NO |
CVE-2021-4118HIGH pytorch-lightning is vulnerable to Deserialization of Untrusted Data | Dec 23, 2021 | 7.8 | 26 | NO | NO |
CVE-2024-8019CRITICAL In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` | Mar 20, 2025 | 9.1 | 24 | NO | NO |
CVE-2022-0845CRITICAL Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0. | Mar 5, 2022 | 9.8 | 24 | NO | NO |
CVE-2024-8020HIGH A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the `/api/v1/state` endpoin | Mar 20, 2025 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Pytorch Lightning
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.6.3 | 1 | 9.8 | 0.4% | 0 | 0 |
| 2.6.2 | 1 | 9.8 | 0.4% | 0 | 0 |
| 2.3.2 | 2 | 8.3 | 0.8% | 0 | 0 |