Skip to main content

Vendor/product archive

lightningai / pytorch_lightning CVEs

Beta · best-effort

8 CVEs tagged to lightningai / pytorch_lightning5 Critical, 3 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-44484

Published May 14, 2026

PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting m…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-31221

Published May 12, 2026

PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpo…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-8020

Published Mar 20, 2025

A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the `/api/v1/state` endpoi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8019

Published Mar 20, 2025

In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-5980

Published Jun 27, 2024

A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningAp…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-5452

Published Jun 6, 2024

A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagemen…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1