Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Oneflow

First CVE: Jun 6, 2024Active for: 2 yearsTotal CVEs: 29
40.8
VTI Score
High

Oneflow is a contract-lifecycle-management platform that occupies a specialized role in enterprise document workflow and e-signature processes. The vendor's vulnerability exposure concentrates in its core platform and recurs through input-handling and resource-management weakness classes—improper input validation, uncontrolled resource consumption, and array-indexing errors—that are characteristic of web applications processing structured document data and user-supplied parameters. While the vendor's CVE footprint is modest in absolute volume, its prominence reflects the critical role contract automation plays in business operations and the dependency organizations place on the integrity of signed agreements handled by such platforms. Defenders should monitor this vendor's disclosures for issues affecting document processing pipelines and access controls; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 97% of tracked vendors
9.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Oneflow over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 6, 2024
2 years ago
Most Recent CVE
Jan 29, 2026
176 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-65890HIGH
A device-ID validation flaw in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) by calling flow.cuda.synchronize() with an invalid or out-of-range GPU device inde
Jan 28, 20267.527NONO
CVE-2025-65889HIGH
A type validation flaw in the flow.dstack() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Jan 28, 20267.527NONO
CVE-2025-65888HIGH
A dimension validation flaw in the flow.empty() component of OneFlow 0.9.0 allows attackers to cause a Denial of Service (DoS) via a negative or excessively large dimension value.
Jan 28, 20267.527NONO
CVE-2025-65886HIGH
A shape mismatch vulnerability in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via supplying crafted tensor shapes.
Jan 28, 20267.527NONO
CVE-2025-70999HIGH
A GPU device-ID validation flaw in the flow.cuda.get_device_capability() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted device ID.
Jan 28, 20267.526NONO
CVE-2025-65891HIGH
A GPU device-ID validation flaw in OneFlow v0.9.0 allows attackers to trigger a Denial of Dervice (DoS) by invoking flow.cuda.get_device_properties() with an invalid or negative de
Jan 28, 20267.526NONO
CVE-2025-71007HIGH
An input validation vulnerability in the oneflow.index_add component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Jan 28, 20267.525NONO
CVE-2024-36736CRITICAL
An issue in the oneflow.permute component of OneFlow-Inc. Oneflow v0.9.1 causes an incorrect calculation when the same dimension operation is performed.
Jun 6, 20249.825NONO
CVE-2025-71001MEDIUM
A segmentation violation in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Jan 28, 20266.524NONO
CVE-2025-71000HIGH
An issue in the flow.cuda.BoolTensor component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Jan 28, 20267.524NONO
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
38%
59%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (10.3%)
Network26 (89.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None23 (79.3%)
Unknown0 (0.0%)
Required6 (20.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None29 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Oneflow.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Oneflow — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Oneflow's Products

View all 1 CNAs →

Top CWEs