Oneflow is a contract-lifecycle-management platform that occupies a specialized role in enterprise document workflow and e-signature processes. The vendor's vulnerability exposure concentrates in its core platform and recurs through input-handling and resource-management weakness classes—improper input validation, uncontrolled resource consumption, and array-indexing errors—that are characteristic of web applications processing structured document data and user-supplied parameters. While the vendor's CVE footprint is modest in absolute volume, its prominence reflects the critical role contract automation plays in business operations and the dependency organizations place on the integrity of signed agreements handled by such platforms. Defenders should monitor this vendor's disclosures for issues affecting document processing pipelines and access controls; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oneflow over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65890HIGH A device-ID validation flaw in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) by calling flow.cuda.synchronize() with an invalid or out-of-range GPU device inde | Jan 28, 2026 | 7.5 | 27 | NO | NO |
CVE-2025-65889HIGH A type validation flaw in the flow.dstack() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Jan 28, 2026 | 7.5 | 27 | NO | NO |
CVE-2025-65888HIGH A dimension validation flaw in the flow.empty() component of OneFlow 0.9.0 allows attackers to cause a Denial of Service (DoS) via a negative or excessively large dimension value. | Jan 28, 2026 | 7.5 | 27 | NO | NO |
CVE-2025-65886HIGH A shape mismatch vulnerability in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via supplying crafted tensor shapes. | Jan 28, 2026 | 7.5 | 27 | NO | NO |
CVE-2025-70999HIGH A GPU device-ID validation flaw in the flow.cuda.get_device_capability() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted device ID. | Jan 28, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-65891HIGH A GPU device-ID validation flaw in OneFlow v0.9.0 allows attackers to trigger a Denial of Dervice (DoS) by invoking flow.cuda.get_device_properties() with an invalid or negative de | Jan 28, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-71007HIGH An input validation vulnerability in the oneflow.index_add component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Jan 28, 2026 | 7.5 | 25 | NO | NO |
CVE-2024-36736CRITICAL An issue in the oneflow.permute component of OneFlow-Inc. Oneflow v0.9.1 causes an incorrect calculation when the same dimension operation is performed. | Jun 6, 2024 | 9.8 | 25 | NO | NO |
CVE-2025-71001MEDIUM A segmentation violation in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Jan 28, 2026 | 6.5 | 24 | NO | NO |
CVE-2025-71000HIGH An issue in the flow.cuda.BoolTensor component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Jan 28, 2026 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oneflow.
Media articles that mention a CVE ID that affects a product developed by Oneflow — matched by CVE ID, not by vendor name.