PyTorch's vulnerability footprint centers narrowly on TorchServe, its model serving and inference framework, which exposes machine-learning models to external requests and presents an attack surface around deployment and resource access. The recurrent weakness classes—including resource-exposure issues, path traversal, server-side request forgery, and name-resolution flaws—reflect the framework's role in bridging untrusted client requests to backend model execution and file systems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pytorch over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-43654CRITICAL TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper input validation, enabling third parties to invoke remote H | Sep 28, 2023 | 9.8 | 70 | NO | YES |
CVE-2024-35198CRITICAL TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. TorchServe 's check on allowed_urls configuration can be by-passed if the URL co | Jul 19, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-35199HIGH TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. In affected versions the two gRPC ports 7070 and 7071, are not bound to [localho | Jul 19, 2024 | 8.2 | 24 | NO | NO |
CVE-2023-48299MEDIUM TorchServe is a tool for serving and scaling PyTorch models in production. Starting in version 0.1.0 and prior to version 0.9.0, using the model/workflow management API, there is a | Nov 21, 2023 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pytorch.
Media articles that mention a CVE ID that affects a product developed by Pytorch — matched by CVE ID, not by vendor name.