Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

paddlepaddle — Vulnerabilities & Security Advisories 31

Browse all 31 CVE security advisories affecting paddlepaddle. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PaddlePaddle is an open-source deep learning platform developed by Baidu, primarily utilized for building and deploying machine learning models in enterprise environments. Its architecture involves complex computational graphs and extensive integration with underlying system libraries, which has historically exposed it to various vulnerability classes. Security audits have identified thirty-one Common Vulnerabilities and Exposures (CVEs), predominantly involving remote code execution, buffer overflows, and improper input validation within its C++ core components. These flaws often stem from insufficient bounds checking in tensor operations or insecure handling of serialized model data. While no widespread, high-profile incidents have disrupted global infrastructure, the sheer volume of disclosed issues highlights significant technical debt in legacy modules. Developers are advised to maintain strict version control and apply patches promptly to mitigate risks associated with these known weaknesses in the framework’s execution engine.

Found 6 results / 31Clear Filters
Top products by paddlepaddle: PaddlePaddle paddlepaddle/paddle
CVE IDTitleCVSSSeverityPublished
CVE-2024-1603 confirmed — paddlepaddle/paddleCWE-73 8.1 -2024-03-23
CVE-2024-0818 PaddlePaddle 路径遍历漏洞 — paddlepaddle/paddleCWE-22 9.1AICriticalAI2024-03-07
CVE-2024-0917 paddlepaddle 代码注入漏洞 — paddlepaddle/paddleCWE-94 8.1AIHighAI2024-03-07
CVE-2024-0815 PaddlePaddle 操作系统命令注入漏洞 — paddlepaddle/paddleCWE-78 9.8AICriticalAI2024-03-07
CVE-2024-0817 PaddlePaddle 命令注入漏洞 — paddlepaddle/paddleCWE-77 8.4AIHighAI2024-03-07
CVE-2024-0521 Code Injection in paddlepaddle/paddle — paddlepaddle/paddleCWE-94 9.8 -2024-01-20

This page lists every published CVE security advisory associated with paddlepaddle. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.