← Back

Horovod

horovod

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Horovod
horovod

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Horovod
1Horovod
Dec 11, 2025
Mar 20, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability is due to improper handling of base64-encoded data in the `ElasticRendezvousHandler`, a subclass of...Show more
Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability is due to improper handling of base64-encoded data in the `ElasticRendezvousHandler`, a subclass of `KVStoreHandler`. Specifically, the `_put_value` method in `ElasticRendezvousHandler` calls `codec.loads_base64(value)`, which eventually invokes `cloudpickle.loads(decoded)`. This allows an attacker to send a malicious pickle object via a PUT request, leading to arbitrary code execution on the server.Show less
1Horovod
1Horovod
Nov 21, 2024
Mar 24, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0.