44 Total advisories
44 Vulnerabilities
0 Malware

Dependency scanning

Check whether torch is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

LOW 3.3
PyPI

CVE-2025-3730

PyTorch Improper Resource Shutdown or Release vulnerability

LOW 3.3
PyPI

CVE-2025-2953

PyTorch susceptible to local Denial of Service

MEDIUM 5.3
PyPI

CVE-2025-3000

PyTorch is vulnerable to memory corruption through its torch.jit.script function

CRITICAL 9.8
PyPI

CVE-2024-7804

Withdrawn Advisory: PyTorch deserialization vulnerability

UNKNOWN
PyPI

CVE-2025-32434

PyTorch: `torch.load` with `weights_only=True` leads to remote code execution

UNKNOWN
PyPI

CVE-2024-31580

CVE-2024-31580

HIGH 7.5
PyPI

CVE-2024-31580

PyTorch heap buffer overflow vulnerability

UNKNOWN
PyPI

CVE-2025-2999

CVE-2025-2999

UNKNOWN
PyPI

CVE-2025-3000

CVE-2025-3000

UNKNOWN
PyPI

CVE-2025-3001

CVE-2025-3001

HIGH 8.8
PyPI

CVE-2026-24747

CVE-2026-24747

LOW 3.3
PyPI

CVE-2025-3730

PyTorch Improper Resource Shutdown or Release vulnerability

MEDIUM 5.3
PyPI

CVE-2025-3001

PyTorch is vulnerable to memory corruption through its torch.lstm_cell function

UNKNOWN
PyPI

CVE-2022-45907

CVE-2022-45907

UNKNOWN
PyPI

CVE-2024-31583

CVE-2024-31583

MEDIUM 5.3
PyPI

CVE-2025-2999

PyTorch is vulnerable to memory corruption through its unpack_sequence function

UNKNOWN
PyPI

CVE-2025-2998

CVE-2025-2998

UNKNOWN
PyPI

CVE-2025-2149

CVE-2025-2149

HIGH 7.5
PyPI

CVE-2025-2148

CVE-2025-2148

MEDIUM 5.5
PyPI

CVE-2025-2953

CVE-2025-2953

MEDIUM 5.3
PyPI

CVE-2025-2998

PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function

LOW 2.5
PyPI

CVE-2025-2149

PyTorch: Manipulation of the argument scale/zero_point leads to improper initialization via Quantized Sigmoid Module

MEDIUM 5.0
PyPI

CVE-2025-2148

PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument

UNKNOWN
PyPI

CVE-2025-3136

CVE-2025-3136

HIGH 7.8
PyPI

CVE-2026-4538

CVE-2026-4538

LOW 3.3
PyPI

CVE-2025-63396

CVE-2025-63396

MEDIUM 5.5
PyPI

CVE-2025-3121

CVE-2025-3121

HIGH 7.5
PyPI

CVE-2025-55560

CVE-2025-55560

HIGH 7.5
PyPI

CVE-2025-55558

CVE-2025-55558

HIGH 7.5
PyPI

CVE-2025-55557

CVE-2025-55557

MEDIUM 5.3
PyPI

CVE-2025-55554

CVE-2025-55554

HIGH 7.5
PyPI

CVE-2025-55553

CVE-2025-55553

HIGH 7.5
PyPI

CVE-2025-55552

CVE-2025-55552

HIGH 7.5
PyPI

CVE-2025-55551

CVE-2025-55551

MEDIUM 5.3
PyPI

CVE-2025-46153

CVE-2025-46153

MEDIUM 5.3
PyPI

CVE-2025-46152

CVE-2025-46152

MEDIUM 5.3
PyPI

CVE-2025-46150

CVE-2025-46150

MEDIUM 5.3
PyPI

CVE-2025-46149

CVE-2025-46149

MEDIUM 5.3
PyPI

CVE-2025-46148

CVE-2025-46148

CRITICAL 9.8
PyPI

CVE-2024-48063

CVE-2024-48063

HIGH 7.8
PyPI

CVE-2024-31583

Pytorch use-after-free vulnerability

UNKNOWN
PyPI

CVE-2024-31584

CVE-2024-31584

CRITICAL 9.8
PyPI

CVE-2025-32434

CVE-2025-32434

CRITICAL 9.8
PyPI

CVE-2022-45907

PyTorch vulnerable to arbitrary code execution

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes