{"id":"CVE-2021-4118","aliases":["GHSA-2vj5-px25-gjrp","PYSEC-2021-874"],"url":"https://o3.security/vulnerability/CVE-2021-4118","summary":"pytorch-lightning is vulnerable to Deserialization of Untrusted Data","details":"pytorch-lightning is vulnerable to Deserialization of Untrusted Data","published":"2021-12-23T18:15:07.407Z","modified":"2026-08-07T19:48:36.626471Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":{"score":0.00978,"percentile":0.58751,"asOf":"2026-08-04"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"pytorch-lightning","fixedVersion":"1.6.0"}],"fix":{"url":"https://github.com/pytorchlightning/pytorch-lightning/commit/62f1e82e032eb16565e676d39e0db0cac7e34ace","label":"pytorchlightning/pytorch-lightning@62f1e82"},"references":[{"type":"FIX","url":"https://github.com/pytorchlightning/pytorch-lightning/commit/62f1e82e032eb16565e676d39e0db0cac7e34ace"},{"type":"FIX","url":"https://huntr.dev/bounties/31832f0c-e5bb-4552-a12c-542f81f111e6"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T19:48:36.626471Z"}}