13 Total advisories
12 Vulnerabilities
1 Malware
Dependency scanning
Check whether lightning is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Malware Advisories
Vulnerabilities
UNKNOWN
CVE-2022-0845
CVE-2022-0845
CRITICAL 9.8
CVE-2026-44484
Compromise of PyTorch Lightning PyPi Package Versions
UNKNOWN
CVE-2021-4118
CVE-2021-4118
CRITICAL 9.1
CVE-2024-5980
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
CRITICAL 9.1
CVE-2024-5980
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
CRITICAL 9.8
CVE-2024-5452
Remote code execution in pytorch lightning
CRITICAL 9.8
CVE-2024-5452
Remote code execution in pytorch lightning
HIGH 7.8
CVE-2026-31221
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
CRITICAL 9.1
CVE-2024-8019
PyTorch Lightning path traversal vulnerability
HIGH 7.5
CVE-2024-8020
PyTorch Lightning denial of service vulnerability
UNKNOWN
CVE-2026-58659
CVE-2026-58659
HIGH 7.8
CVE-2026-58659
PyTorch Lightning allows arbitrary code execution through checkpoint _instantiator hyperparameters
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes