PT-2026-29577 · Microsoft · Onnx
Zeroxjacks
·
Published
2026-04-01
·
Updated
2026-04-09
·
CVE-2026-34445
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
ONNX versions prior to 1.21.0
Description
The ExternalDataInfo class in ONNX used Python’s
setattr() function to load metadata from ONNX model files without validating the keys. This allowed an attacker to craft a malicious model that could overwrite internal object properties. Exploitation could lead to a denial-of-service (DoS) condition by causing excessive memory allocation, access bypass by reading unintended file parts, or object corruption through the injection of dunder attributes.Recommendations
Update to ONNX version 1.21.0 or later.
Fix
Resource Exhaustion
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Onnx