{"id":"PYSEC-2026-3249","summary":"Out of bounds read in Tensorflow","details":"### Impact\nTensorFlow's [type inference](https://github.com/tensorflow/tensorflow/blob/274df9b02330b790aa8de1cee164b70f72b9b244/tensorflow/core/graph/graph.cc#L223-L229) can cause a heap OOB read as the bounds checking is done in a `DCHECK` (which is a no-op during production):\n\n```cc\nif (node_t.type_id() != TFT_UNSET) {\n  int ix = input_idx[i];\n  DCHECK(ix \u003c node_t.args_size())\n      \u003c\u003c \"input \" \u003c\u003c i \u003c\u003c \" should have an output \" \u003c\u003c ix\n      \u003c\u003c \" but instead only has \" \u003c\u003c node_t.args_size()\n      \u003c\u003c \" outputs: \" \u003c\u003c node_t.DebugString();\n  input_types.emplace_back(node_t.args(ix));\n  // ...\n}       \n```   \n      \nAn attacker can control `input_idx` such that `ix` would be larger than the number of values in `node_t.args`.\n        \n### Patches\nWe have patched the issue in GitHub commit [c99d98cd189839dcf51aee94e7437b54b31f8abd](https://github.com/tensorflow/tensorflow/commit/c99d98cd189839dcf51aee94e7437b54b31f8abd).\n  \nThe fix will be included in TensorFlow 2.8.0. This is the only affected version.\n\n### For more information\nPlease consult [our security guide](https://github.com/tensorflow/tensorflow/blob/master/SECURITY.md) for more information regarding the security model and how to contact us with issues and questions.","aliases":["BIT-tensorflow-2022-23592","CVE-2022-23592","GHSA-vq36-27g6-p492","PYSEC-2022-101","PYSEC-2022-156"],"modified":"2026-07-13T16:43:45.786983761Z","published":"2026-07-09T16:49:40.607200Z","references":[{"type":"WEB","url":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-vq36-27g6-p492"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23592"},{"type":"WEB","url":"https://github.com/tensorflow/tensorflow/commit/c99d98cd189839dcf51aee94e7437b54b31f8abd"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow-cpu/PYSEC-2022-101.yaml"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow-gpu/PYSEC-2022-156.yaml"},{"type":"WEB","url":"https://github.com/tensorflow/tensorflow"},{"type":"WEB","url":"https://github.com/tensorflow/tensorflow/blob/274df9b02330b790aa8de1cee164b70f72b9b244/tensorflow/core/graph/graph.cc#L223-L229"},{"type":"PACKAGE","url":"https://pypi.org/project/tensorflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vq36-27g6-p492"}],"affected":[{"package":{"name":"tensorflow","ecosystem":"PyPI","purl":"pkg:pypi/tensorflow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.8.0-rc0"},{"fixed":"2.8.0"}]}],"versions":["2.8.0-rc0","2.8.0rc0","2.8.0rc1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/tensorflow/PYSEC-2026-3249.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N"}]}