What is CVE-2026-63632?
CVE-2026-63632 is a vulnerability in Open Neural Network Exchange (ONNX) from versions 1.3.0 through 1.22.0. The `onnx.version_converter.convert_version()` function can trigger an out-of-bounds read in `Gemm_7_6::adapt_gemm_7_6()` when a Gemm node is improperly handled. Attackers can leak information via a crafted ONNX model; affected users should immediately update to a version above 1.22.0.
Azərbaycanca: CVE-2026-63632, Open Neural Network Exchange (ONNX) standartında 1.3.0-dan 1.22.0 versiyalarına qədər mövcud olan boşluqdur. `onnx.version_converter.convert_version()` funksiyası, `Gemm` node-unun daxiletmələri düzgün işlənmədikdə `Gemm_7_6::adapt_gemm_7_6()` funksiyasında out-of-bounds read zəifliyinə yol aça bilər. Hücumçu xüsusi hazırlanmış ONNX modeli vasitəsilə məlumat sızması həyata keçirə bilər, təsirlənən versiyaları istifadə edənlər dərhal 1.22.0-dən yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Which versions of ONNX are affected by CVE-2026-63632?
The vulnerability exists in ONNX versions 1.3.0 through 1.22.0.
What can an attacker achieve by exploiting CVE-2026-63632?
An attacker can leak information via a crafted ONNX model.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.