CVE-2026-63632: Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in...
Added to the CISA Known Exploited Vulnerabilities catalog on 18 Aug 2026. Vendor: AI/ML. Product: machine learning. CVSS score: 3.3.
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input...
Required action: Review and patch if applicable to your AI infrastructure.