{"id":"CVE-2021-4118","aliases":["GHSA-2vj5-px25-gjrp","PYSEC-2021-874","PYSEC-2026-3968"],"url":"https://o3.security/vulnerability/CVE-2021-4118","summary":"pytorch-lightning is vulnerable to Deserialization of Untrusted Data","details":"pytorch-lightning is vulnerable to Deserialization of Untrusted Data","published":"2021-12-23T18:15:07.407Z","modified":"2026-09-10T17:26:03.425101162Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":{"score":0.00978,"percentile":0.60447,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"pytorch-lightning","fixedVersion":"1.6.0"}],"fix":{"url":"https://github.com/pytorchlightning/pytorch-lightning/commit/62f1e82e032eb16565e676d39e0db0cac7e34ace","label":"pytorchlightning/pytorch-lightning@62f1e82"},"references":[{"type":"FIX","url":"https://github.com/pytorchlightning/pytorch-lightning/commit/62f1e82e032eb16565e676d39e0db0cac7e34ace"},{"type":"FIX","url":"https://huntr.dev/bounties/31832f0c-e5bb-4552-a12c-542f81f111e6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-4118"},{"type":"WEB","url":"https://github.com/PyTorchLightning/pytorch-lightning/issues/11045"},{"type":"WEB","url":"https://github.com/PyTorchLightning/pytorch-lightning/pull/11099"},{"type":"WEB","url":"https://github.com/PyTorchLightning/pytorch-lightning/releases/tag/1.6.0"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2vj5-px25-gjrp"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pytorch-lightning/PYSEC-2021-874.yaml"},{"type":"PACKAGE","url":"https://github.com/pytorchlightning/pytorch-lightning"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T17:26:03.425101162Z"}}