Onnx
Vendor:
First CVE: Jan 26, 2023 · Active for 3 years
11
Total CVEs
More Total CVEs than 89% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Onnx over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 26, 2023
3 years ago
Most Recent CVE
Jul 8, 2026
16 days ago
CVE Severity & Scoring
Onnx11 CVEs
27%
55%
18%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (27.3%)
Network8 (72.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (54.5%)
Unknown0 (0.0%)
Required5 (45.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-28500CRITICAL Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub. | Mar 18, 2026 | 9.1 | 35 | NO | NO |
CVE-2026-34445HIGH Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setatt | Apr 1, 2026 | 8.6 | 31 | NO | NO |
CVE-2026-27489HIGH Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read ar | Apr 1, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-44512MEDIUM Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.convert_version() can dereference a | Jul 8, 2026 | 5.5 | 25 | NO | NO |
CVE-2025-51480HIGH Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.locatio | Jul 22, 2025 | 8.8 | 25 | NO | NO |
CVE-2024-5187HIGH A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due to inadequate prevention of path | Jun 6, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-27319CRITICAL Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy. | Feb 23, 2024 | 9.1 | 24 | NO | NO |
CVE-2022-25882HIGH Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the mod | Jan 26, 2023 | 7.5 | 24 | NO | NO |
CVE-2026-34447MEDIUM Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a symlink traversal vulnerability in external data | Apr 1, 2026 | 5.5 | 22 | NO | NO |
CVE-2026-34446MEDIUM Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is an issue in onnx.load, the code checks for symlinks | Apr 1, 2026 | 5.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Onnx
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.17.0 | 1 | 8.8 | 0.6% | 0 | 0 |
| 1.16.0 | 1 | 8.8 | 1.2% | 0 | 0 |