PaddlePaddle is a machine-learning framework and deep-learning platform with a focused but strategically important footprint in AI/ML infrastructure and research tooling. Despite a narrow product portfolio, the vendor's presence spans model development, training, and inference across academic and enterprise deployments, presenting a meaningful attack surface in the ML-tooling supply chain. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through weakness classes including divide-by-zero conditions, OS command injection, NULL-pointer dereferences, buffer overflows, and code-injection flaws that are characteristic of large numerical-computing codebases with native components and dynamic code execution. The exposure concentrates in the core PaddlePaddle framework and related tools, reflecting the complexity and memory-safety demands of interpreted and compiled layers in deep-learning platforms. Defenders should treat this vendor's security advisories as high-priority, particularly given the framework's role in model pipelines; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Paddlepaddle over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-52314CRITICAL PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbitrary commands on the operating system.
| Jan 3, 2024 | 9.8 | 30 | NO | NO |
CVE-2022-46742CRITICAL Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution.
| Dec 7, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-52304CRITICAL Stack overflow in paddle.searchsorted in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.
| Jan 3, 2024 | 9.8 | 29 | NO | NO |
CVE-2022-46741CRITICAL Out-of-bounds read in gather_tree in PaddlePaddle before 2.4. | Dec 7, 2022 | 9.1 | 29 | NO | NO |
CVE-2024-0818CRITICAL Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6 | Mar 7, 2024 | 9.1 | 28 | NO | NO |
CVE-2022-31523CRITICAL The PaddlePaddle/Anakin repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | Jul 11, 2022 | 9.3 | 28 | NO | NO |
CVE-2023-38673CRITICAL PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system.
| Jul 26, 2023 | 9.8 | 27 | NO | NO |
CVE-2024-0917CRITICAL remote code execution in paddlepaddle/paddle 2.6.0 | Mar 7, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-52310CRITICAL PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on the operating system.
| Jan 3, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-38671CRITICAL Heap buffer overflow in paddle.trace in PaddlePaddle before 2.5.0. This flaw can lead to a denial of service, information disclosure, or more damage is possible.
| Jul 26, 2023 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Paddlepaddle.
Media articles that mention a CVE ID that affects a product developed by Paddlepaddle — matched by CVE ID, not by vendor name.