CVE-2025-71000
7.5OneFlow · OneFlow
A vulnerability in the OneFlow cuda.BoolTensor component allows unauthenticated remote attackers to trigger a Denial of Service via crafted input.
Executive summary
The OneFlow v0.9.0 machine learning framework contains a critical vulnerability that allows unauthenticated attackers to crash the system via a Denial of Service attack.
Vulnerability
This vulnerability resides within the cuda.BoolTensor component of the OneFlow framework. It allows an unauthenticated, remote attacker to trigger a Denial of Service condition by supplying a specially crafted input to the affected component.
Business impact
The ability for an unauthenticated attacker to cause a Denial of Service can result in significant operational disruption and loss of availability for services relying on the OneFlow framework. Given the CVSS score of 7.5, this high-severity vulnerability poses a substantial risk to service continuity. Organizations should prioritize mitigation to avoid unplanned downtime and potential impact on dependent machine learning pipelines.
Remediation
Immediate Action: Monitor the official OneFlow GitHub repository for the release of a patch or security update that addresses this issue.
Proactive Monitoring: Review system and application logs for unusual crashes or patterns of input that could indicate attempts to trigger the vulnerability.
Compensating Controls: Implement network-level filtering or input validation at the application firewall level to restrict access to the affected OneFlow components where possible.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability, combined with the lack of required authentication, necessitates careful monitoring and prompt action once a vendor fix is released. Security teams should track the status of the referenced issue in the OneFlow repository and ensure that automated patching processes are ready to deploy the update as soon as it becomes available.