CVE-2025-55557: n/a
CVE-2025-55557 is a vulnerability in PyTorch version 2.7.0 where a Name Error occurs if a model uses torch.cummin and is compiled by Inductor. This results in a Denial of Service (DoS) condition. The vulnerability has a high severity score of 7.5 and does not affect confidentiality or integrity, only availability. No patch or remediation information is currently provided.
AI Analysis
Technical Summary
In PyTorch version 2.7.0, when a model includes the torch.cummin operation and is compiled using the Inductor compiler, a Name Error can occur. This error leads to a Denial of Service, preventing the model from functioning properly. The issue is tracked as CVE-2025-55557 and is associated with CWE-248 (Uncaught Exception). There is no indication of active exploitation in the wild or available patches at this time.
Potential Impact
The vulnerability causes a Denial of Service by triggering a Name Error during model compilation with Inductor when torch.cummin is used. This impacts availability but does not affect confidentiality or integrity of the system or data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid using torch.cummin in models compiled with Inductor in PyTorch 2.7.0 if possible.
CVE-2025-55557: n/a
Description
CVE-2025-55557 is a vulnerability in PyTorch version 2.7.0 where a Name Error occurs if a model uses torch.cummin and is compiled by Inductor. This results in a Denial of Service (DoS) condition. The vulnerability has a high severity score of 7.5 and does not affect confidentiality or integrity, only availability. No patch or remediation information is currently provided.
CVSS v3.1
Score 7.5high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In PyTorch version 2.7.0, when a model includes the torch.cummin operation and is compiled using the Inductor compiler, a Name Error can occur. This error leads to a Denial of Service, preventing the model from functioning properly. The issue is tracked as CVE-2025-55557 and is associated with CWE-248 (Uncaught Exception). There is no indication of active exploitation in the wild or available patches at this time.
Potential Impact
The vulnerability causes a Denial of Service by triggering a Name Error during model compilation with Inductor when torch.cummin is used. This impacts availability but does not affect confidentiality or integrity of the system or data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid using torch.cummin in models compiled with Inductor in PyTorch 2.7.0 if possible.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- mitre
- Date Reserved
- 2025-08-13T00:00:00.000Z
- State
- PUBLISHED
Threat ID: 68d5da079e21be37e937d096
Added to database: 09/26/2025, 00:10:47 UTC
Last enriched: 09/08/2026, 13:21:50 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 343
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.