CVE-2026-11329
LOW
2,0
Source: [email protected]
Attack Vector: local
Attack Complexity: high
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
LOW
3,6
Source: [email protected]
Attack Vector: local
Attack Complexity: high
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: low
LOW
2,4
Source: [email protected]
Access Vector: local
Access Complexity: high
Authentication: single
Confidentiality: none
Integrity: partial
Availability: partial
Description
AI Translation Available
A vulnerability has been found in onnx onnx-mlir up to 0.5.0.0. Affected by this issue is the function generate_hash_key of the file src/Runtime/python/torch_onnxmlir/src/torch_onnxmlir/backend.py of the component Placeholder Node Cache Handler. Such manipulation leads to use of weak hash. An attack has to be approached locally. A high complexity level is associated with this attack. The exploitation is known to be difficult. The name of the patch is 72c5187ff6d13c2c2b3d3789b8f5faf99f08a5b4. Applying a patch is advised to resolve this issue.
327
Use of a Broken or Risky Cryptographic Algorithm
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Accountability
Non-Repudiation
Potential Impacts:
Read Application Data
Modify Application Data
Hide Activities
Applicable Platforms
Languages:
Not Language-Specific, Verilog, VHDL
Technologies:
Not Technology-Specific, ICS/OT
328
Use of Weak Hash
DraftCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Applicable Platforms
Technologies:
ICS/OT
https://github.com/onnx/onnx-mlir/
https://github.com/onnx/onnx-mlir/commit/72c5187ff6d13c2c2b3d3789b8f5faf99f08a5…
https://github.com/onnx/onnx-mlir/pull/3427
https://vuldb.com/cve/CVE-2026-11329
https://vuldb.com/submit/832358
https://vuldb.com/vuln/368865
https://vuldb.com/vuln/368865/cti