Arbitrary Attribute Overwrite in Open Neural Network Exchange (ONNX)
CVE-2026-34445

8.6HIGH

Key Information:

Vendor

Onnx

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2026-34445?

The ExternalDataInfo class in Open Neural Network Exchange (ONNX) enabled loading of metadata directly from ONNX model files without validating the 'keys' present. This oversight allowed attackers to craft malicious models capable of overwriting internal object properties, potentially compromising the integrity of machine learning applications. This vulnerability has been addressed in version 1.21.0, which enhances metadata handling to prevent such arbitrary attribute overwrites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

onnx < 1.21.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.