pytorch-lightning
PyTorch Lightning is the lightweight PyTorch wrapper for ML researchers. Scale your models. Write less boilerplate.
Activity
- Latest release
- 5d ago
- Total releases
- 223
- Cadence
- ~14 days
- Last 12 months
- 7
Details
- License
- Apache-2.0
- First release
- Mar 31, 2019
| Version | Released | |
|---|---|---|
2.6.6
patch
| ||
2.6.5
patch
1 CVE
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.6.4
patch
1 CVE
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.6.1
patch
1 CVE
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.6.0
minor
2 CVEs
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.5.6
patch
2 CVEs
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.6.0.dev0
pre
2 CVEs
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.5.5
patch
2 CVEs
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.5.4
patch
2 CVEs
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.5.3
patch
2 CVEs
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.5.2
patch
2 CVEs
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.5.1.post0
pre
2 CVEs
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.5.1
patch
2 CVEs
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.5.1rc2
pre
2 CVEs
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.5.1rc1
pre
2 CVEs
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.5.1rc0
pre
2 CVEs
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.5.0.post0
pre
2 CVEs
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.5.0
minor
2 CVEs
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
1.6.5.post0
pre
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.10.post0
pre
8 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-0845
GHSA-r5qj-cvf9-p85h
PYSEC-2022-181
PYSEC-2026-3969
Mar 06, 2022
Code Injection in PyTorch Lightning
Critical
Network
Low
None
None
PyTorch Lightning version 1.5.10 and prior is vulnerable to code injection. An attacker could execute commands on the target OS running the operating system by setting the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 119 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0rc0
1.6.0rc1
Fixed in
1.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-4118
GHSA-2vj5-px25-gjrp
PYSEC-2021-874
PYSEC-2026-3968
Jan 06, 2022
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
High
Local
Low
None
pytorch-lightning is vulnerable to Deserialization of Untrusted Data. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 119 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0rc0
1.6.0rc1
Fixed in
1.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.5.0rc0
pre
2 CVEs
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.4.0
minor
2 CVEs
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.3.3
patch
3 CVEs
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.3.2
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.3.1
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.3.0
minor
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.5
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.4
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.3
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.2
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.1
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.0.post0
pre
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.0
minor
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.0rc0
pre
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.4
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.3
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.2
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.1
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.0
minor
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.0rc1
pre
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.9.post0
pre
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.9
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.8
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.0rc0
pre
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.7
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.6
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.5
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.4
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.3
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.2
patch
6 CVEs
CVE-2024-5980
PYSEC-2026-3975
GHSA-mr7h-w2qc-ffc2
PYSEC-2026-386
Sep 10, 2026
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-5452
PYSEC-2026-3974
GHSA-cgwc-qvrx-rf7f
PYSEC-2026-385
Sep 10, 2026
Remote code execution in pytorch lightning
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 205 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.0.dev20240318
2.3.0.dev20240324
2.3.0.dev20240328
2.3.0.dev20240331
2.3.0.dev20240407
2.3.0.dev20240414
2.3.0.dev20240421
2.3.0.dev20240428
2.3.0.dev20240505
2.3.0.dev20240519
2.3.0.dev20240526
2.3.0.dev20240602
2.3.0.dev20240609
2.3.0.dev20240616
2.3.0.dev20240623
2.3.1
2.3.2
Fixed in
2.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-58659
PYSEC-2026-3967
GHSA-qqmf-gpg7-g8gw
PYSEC-2026-3624
Jul 15, 2026
Critical
Local
Low
None
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 210 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
2.6.1
2.6.4
2.6.5
Fixed in
2.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31221
PYSEC-2026-3043
GHSA-75m9-98v2-hjpm
PYSEC-2026-3972
Jul 13, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded. Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 207 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.post0
2.5.0rc0
2.5.1
2.5.1.post0
2.5.1rc0
2.5.1rc1
2.5.1rc2
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.6.0
2.6.0.dev0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8020
PYSEC-2026-1857
GHSA-98fp-7v67-4v3q
PYSEC-2026-3971
Jul 07, 2026
PyTorch Lightning denial of service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 190 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-8019
PYSEC-2026-507
GHSA-4cv3-v7pv-rfhf
PYSEC-2026-3970
Jun 29, 2026
PyTorch Lightning path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the Affected versions
0.0.2
0.10.0
0.2
0.2.2
0.2.3
0.2.4
0.2.4.1
0.2.5
0.2.5.1
0.2.5.2
0.2.6
0.3
+ 191 more Show less
0.3.1
0.3.2
0.3.3
0.3.4
0.3.4.1
0.3.5
0.3.6
0.3.6.1
0.3.6.3
0.3.6.4
0.3.6.5
0.3.6.6
0.3.6.7
0.3.6.8
0.3.6.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.1.2
0.5.1.3
0.5.2
0.5.2.1
0.5.3
0.5.3.1
0.5.3.2
0.5.3.3
0.6.0
0.7.1
0.7.3
0.7.5
0.7.6
0.8.1
0.8.3
0.8.4
0.8.5
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.10
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.7.post0
1.3.8
1.4.0
1.4.0rc0
1.4.0rc1
1.4.0rc2
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0rc0
1.5.0rc1
1.5.1
1.5.10
1.5.10.post0
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.0rc0
1.6.0rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.post0
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.0.post1
1.8.0rc0
1.8.0rc1
1.8.0rc2
1.8.1
1.8.2
1.8.3
1.8.3.post0
1.8.3.post1
1.8.3.post2
1.8.4
1.8.4.post0
1.8.5
1.8.5.post0
1.8.6
1.9.0
1.9.0rc0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
2.0.0
2.0.0rc0
2.0.1
2.0.1.post0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.9.post0
2.1.0
2.1.0rc0
2.1.0rc1
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.post0
2.2.0rc0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.3.1
2.3.2
2.3.3
Fixed in
2.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |