tensorflow@2.21.0rc0 vulnerabilities

TensorFlow is an open source machine learning framework for everyone.

Direct Vulnerabilities

Known vulnerabilities in the tensorflow package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Allocation of Resources Without Limits or Throttling

tensorflow is a machine learning framework.

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the tf.keras.layers.Conv2D function when the padding parameter is set to 'valid'. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition.

How to fix Allocation of Resources Without Limits or Throttling?

There is no fixed version for tensorflow.

[0,)
  • M
Incorrect Calculation

tensorflow is a machine learning framework.

Affected versions of this package are vulnerable to Incorrect Calculation via the Embedding operator that always outputs 0 without XLA when input_dim=1 is set. An attacker can cause the application to produce unpredictable or incorrect outputs by triggering compilation of the affected component.

How to fix Incorrect Calculation?

There is no fixed version for tensorflow.

[0,)