OSS Support Hub / Machine Learning

Python Machine Learning Apache-2.0 Latest: v1.22.0

ONNX

Open standard for representing machine learning models enabling interoperability across frameworks

Project Health at a Glance

Live data from GitHub and PyPI, updated daily.

21.1K+152
GitHub Stars
📦
v1.22.0
Latest Release · 14 days ago
🔄
84d
Avg. Release Cadence
🐛
279
Open Issues
📅
Today
Last Commit
🔒
10
Active CVEs

Data last fetched: 2026-06-29

Known Vulnerabilities

10 active CVEs reported via OSV.dev

onnx Vulnerable to Path Traversal via Symlink

Published: 2026-03-31 Fixed in: 1.21.0

ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.

Published: 2026-04-01 Fixed in: 1.21.0

onnx allows Arbitrary File Overwrite in download_model_with_test_data

Published: 2024-06-06 Fixed in: 1.16.2

ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load

Published: 2026-04-01 Fixed in: 1.21.0

Directory Traversal in onnx

Published: 2023-01-26 Fixed in: 1.13.0

Open Neural Network Exchange (ONNX) Path Traversal Vulnerability

Published: 2025-03-20 Fixed in: 1.17.0

Onnx Out-of-bounds Read vulnerability

Published: 2024-02-23 Fixed in: 1.16.0

ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack

Published: 2026-03-16 Fixed in: 1.21.0rc1

ONNX: External Data Symlink Traversal

Published: 2026-04-01 Fixed in: 1.21.0

ONNX: TOCTOU arbitrary file read/write in save_external_dat

Published: 2026-04-01 Fixed in: 1.21.0

Alternatives to ONNX

Other Machine Learning projects in the Python ecosystem worth evaluating.

Support Options for ONNX

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for ONNX — without relying on volunteer maintainers.