CVE-2026-31253 | flash-attention training framework up to 2025-13-04 Pickle checkpoint.py load_checkpoint deserialization
A vulnerability was found in flash-attention training framework up to 2025-13-04. It has been classified as critical. Impacted is the function load_checkpoint of the file checkpoint.py of the component Pickle Module. The manipulation leads to deserialization.
This vulnerability is referenced as CVE-2026-31253. The attack needs to be initiated within the local network. No exploit is available.