PT-2022-3914 · Apache · Apache Mxnet

·

CVE-2022-24294

·

Published

2022-07-24

·

Updated

2026-07-06

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache MXNet versions prior to 1.9.1
Description A regular expression used in Apache MXNet is vulnerable to a potential denial-of-service by excessive resource consumption. The issue could be exploited when loading a model in Apache MXNet that has a specially crafted operator name, causing the regular expression evaluation to use excessive resources to attempt a match.
Recommendations For Apache MXNet versions prior to 1.9.1, update to version 1.9.1 or later to resolve the issue. As a temporary workaround, consider restricting the loading of models with specially crafted operator names to minimize the risk of exploitation.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04732
BIT-MXNET-2022-24294
CVE-2022-24294
GHSA-XXJ3-55P6-XG3H
PYSEC-2026-850

Affected Products

Apache Mxnet