CVE-2026-4538
ADVISORY - nistSummary
A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request but has not reacted yet.
EPSS Score: 0.00023 (0.065)
Common Weakness Enumeration (CWE)
ADVISORY - redhat
Deserialization of Untrusted Data
NIST
CVSS SCORE
1.9lowDebian
CREATED
UPDATED
ADVISORY IDCVE-2026-4538
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Ubuntu
CREATED
UPDATED
ADVISORY IDCVE-2026-4538
EXPLOITABILITY SCORE
1.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
7.8mediumPypA
CREATED
UPDATED
ADVISORY ID
PYSEC-2026-139
EXPLOITABILITY SCORE
1.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
7.8highBitnami
CREATED
UPDATED
ADVISORY ID
BIT-pytorch-2026-4538
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
1.9lowRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2026-4538
EXPLOITABILITY SCORE
1.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)