CVE-2025-3730 | PyTorch 2.6.0 LossCTC.cpp torch.nn.functional.ctc_loss denial of service (Issue 150835 / Nessus ID 235330)
A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2025-3730. An attack has to be approached locally. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.
It is recommended to apply a patch to fix this issue.
The security policy of the project warns to use unknown models which might establish malicious effects.