CVE-2026-14647
MEDIUM
4.3
CVSS 3.1
Description
A weakness has been identified in onnx up to 1.21.x. This vulnerability affects the function convPoolShapeInference_opset19 of the file onnx/defs/nn/old.cc of the component onnxruntime. This manipulation causes out-of-bounds read. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Patch name: a7bf3a0f1d18bb62575236ef6e4944980c40e045. It is recommended to apply a patch to fix this issue.
Metadata
Severity & Metrics
4.3
MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| n/a | onnx | — | 1.0, 1.1, 1.2, 1.3 … |
CVSS scores (4)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 5.3 | MEDIUM | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P |
| 4.3 | MEDIUM | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C |
| 4.3 | MEDIUM | 3.0 | cna | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C |
| 4.0 | N/D | 2.0 | cna | AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:OF/RC:C |
References (8)
- VDB-376160 | onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds https://vuldb.com/vuln/376160
- VDB-376160 | CTI Indicators (IOB, IOC, IOA) https://vuldb.com/vuln/376160/cti
- CVE-2026-14647 | CVE Analysis and Report https://vuldb.com/cve/CVE-2026-14647
- Submit #846317 | onnx unpatched (HEAD); via onnxruntime 1.22.0 bundle Out-of-Bounds Read https://vuldb.com/submit/846317
- https://github.com/onnx/onnx/issues/8036
- https://github.com/onnx/onnx/pull/8051
- https://github.com/onnx/onnx/commit/a7bf3a0f1d18bb62575236ef6e4944980c40e045
- https://github.com/onnx/onnx/