VDB
Sign up
CRITICAL9.1

PYSEC-2026-441

PaddlePaddle Out-of-bounds Read vulnerability

Quick fix

PYSEC-2026-441 — paddlepaddle: upgrade to the fixed version with the command below.

pip install --upgrade 'paddlepaddle>=2.4'

Details

Out-of-bounds read in `gather_tree` in PaddlePaddle before 2.4. A [patch](https://github.com/PaddlePaddle/Paddle/commit/6712e262fc6734873cc6d5ca4f45973339a88697) is available in the `release/2.4` branch.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/paddlepaddle
Introduced in: 0Fixed in: 2.4
Fixpip install --upgrade 'paddlepaddle>=2.4'

References