CVE-2026-34447

EUVD-2026-17989
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a symlink traversal vulnerability in external data loading allows reading files outside the model directory. This issue has been patched in version 1.21.0.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 16.28%
Affected Products (NVD)
VendorProductVersion
linuxfoundationonnx
𝑥
< 1.21.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
onnx
bookworm
no-dsa
bullseye
postponed
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
onnx
jammy
needed
noble
needed
questing
ignored
resolute
needed