Skip to content

VULN UPGRADE: torch (major → 2.10.0) [examples/pytorch/token-classification] - #1

Closed
campaigner-prod[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/major/pip/token-classification/5-1771017368
Closed

VULN UPGRADE: torch (major → 2.10.0) [examples/pytorch/token-classification]#1
campaigner-prod[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/major/pip/token-classification/5-1771017368

Conversation

@campaigner-prod

Copy link
Copy Markdown

Summary: Critical-severity security update — 1 package upgraded (MAJOR changes included)

Manifests changed:

  • examples/pytorch/token-classification (pip)

Updates

Package From To Type Vulnerabilities Fixed
torch 1.3 2.10.0 major 8 CRITICAL, 6 HIGH, 2 MODERATE, 2 MEDIUM, 1 LOW

Warning

Major Version Upgrade

This update includes major version changes that may contain breaking changes. Please:

  • Review the changelog/release notes for breaking changes
  • Test thoroughly in a staging environment
  • Update any code that depends on changed APIs
  • Ensure all tests pass before merging

Security Details

🚨 Critical & High Severity (14 fixed)
Package CVE Severity Summary Unsafe Version Fixed In
torch GHSA-47fc-vmwq-366v CRITICAL PyTorch vulnerable to arbitrary code execution 1.3 1.13.1
torch CVE-2024-48063 critical - 1.3 -
torch PYSEC-2024-259 critical - 1.3 2.5.0
torch GHSA-53q9-r3pm-6pq6 CRITICAL PyTorch: torch.load with weights_only=True leads to remote code execution 1.3 2.6.0
torch CVE-2025-32434 critical PyTorch: torch.load with weights_only=True leads to remote code execution 1.3 -
torch PYSEC-2025-41 critical - 1.3 2.6.0
torch PYSEC-2022-43015 CRITICAL - 1.3 767f6aa49fe20a2766b9843d01e3b7f7793df6a3
torch CVE-2022-45907 CRITICAL - 1.3 -
torch GHSA-pg7h-5qx3-wjr3 HIGH Pytorch use-after-free vulnerability 1.3 2.2.0
torch PYSEC-2024-252 HIGH - 1.3 b5c3a17c2c207ebefcb85043f0cf94be9b2fef81
torch CVE-2024-31580 HIGH - 1.3 -
torch GHSA-5pcm-hx3q-hm94 HIGH PyTorch heap buffer overflow vulnerability 1.3 2.2.0
torch CVE-2024-31583 high - 1.3 -
torch PYSEC-2024-251 high - 1.3 9c7071b0e324f9fb68ab881283d6b8d388a4bcd2
ℹ️ Other Vulnerabilities (5)
Package CVE Severity Summary Unsafe Version Fixed In
torch CVE-2024-31584 medium - 1.3 -
torch PYSEC-2024-250 medium - 1.3 7c35874ad664e74c8e4252d67521f3986eadb0e6
torch CVE-2025-3730 MODERATE - 1.3 -
torch GHSA-887c-mr87-cxwp MODERATE PyTorch Improper Resource Shutdown or Release vulnerability 1.3 2.8.0
torch GHSA-3749-ghw9-m3mg LOW PyTorch susceptible to local Denial of Service 1.3 2.7.1-rc1

Review Checklist

Extra review is recommended for this update:

  • Review changes for compatibility with your code
  • Check release notes for breaking changes
  • Run integration tests to verify service behavior
  • Test in staging environment before production
  • Monitor key metrics after deployment

Update Mode: Vulnerability Remediation (Critical/High)

🤖 Generated by DataDog Automated Dependency Management System

@campaigner-prod campaigner-prod Bot closed this Mar 1, 2026
@campaigner-prod
campaigner-prod Bot deleted the engraver-auto-version-upgrade/major/pip/token-classification/5-1771017368 branch March 1, 2026 15:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants