{"id":"CVE-2026-44512","aliases":["GHSA-hwpq-hmq9-wj77","PYSEC-2026-2689"],"url":"https://o3.security/vulnerability/CVE-2026-44512","summary":"ONNX: Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)","details":"Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.convert_version() can dereference a null pointer in Upsample_6_7::adapt_upsample_6_7() in onnx/version_converter/adapters/upsample_6_7.h when processing an untrusted model with an Upsample node that has zero inputs, causing an unrecoverable denial of service. This issue is fixed in version 1.22.0.","published":"2026-07-08T19:32:04.886Z","modified":"2026-08-12T15:14:59.718334Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},"epss":{"score":0.00193,"percentile":0.08968,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"onnx","fixedVersion":"1.22.0"}],"fix":{"url":"https://github.com/onnx/onnx/commit/cd310408165ad47c3cd7eb2b86cb5b80aa2e4fdf","label":"onnx/onnx@cd31040"},"references":[{"type":"WEB","url":"https://github.com/onnx/onnx/releases/tag/v1.22.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44512.json"},{"type":"ADVISORY","url":"https://github.com/onnx/onnx/security/advisories/GHSA-hwpq-hmq9-wj77"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44512"},{"type":"FIX","url":"https://github.com/onnx/onnx/commit/cd310408165ad47c3cd7eb2b86cb5b80aa2e4fdf"},{"type":"FIX","url":"https://github.com/onnx/onnx/pull/7813"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T15:14:59.718334Z"}}