depscope
Packages
IntegrateAPI DocsCuratorBenchmarkCoverage
Sign inGet API access
depscope/pypi/torch

torch

pypiv2.12.0

Tensors and Dynamic neural networks in Python with strong GPU acceleration

License BSD-3-Clausepermissive47 versions18 deps20,278,236 weekly dl
pytorch/pytorch
60
/ 100
Health
update required

[email protected] has vulnerabilities — update to latest

  • Moderate health score (60/100) — verify manually
  • 1 high severity vulnerabilities
Health breakdown0 – 100
25/25
maintenance
20/20
popularity
8/25
security
12/15
maturity
10/15
community
0/15
popularity_floor
Vulnerabilities
9
1 high6 medium2 low
Advisories (9)
SeverityIDSummaryFixed in
highBIT-pytorch-2025-2148A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.—
lowBIT-pytorch-2025-2149A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zero_point leads to improper initialization. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.—
mediumBIT-pytorch-2025-2998A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.—
mediumBIT-pytorch-2025-2999A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.—
mediumBIT-pytorch-2025-3000A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.—
mediumBIT-pytorch-2025-3001A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.—
mediumBIT-pytorch-2025-3121A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.—
mediumBIT-pytorch-2025-3136A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.—
lowBIT-pytorch-2025-63396An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (DoS).—
Quality signals
OSS Criticality
0.48medium

Health History

Dependency Tree

License Audit

Dependencies (18)
filelocktyping-extensionssetuptoolssympynetworkxjinja2fsspeccuda-toolkit[cudart,cufft,cufile,cupti,curand,cusolver,cusparse,nvjitlink,nvrtc,nvtx]nvidia-cublascuda-bindingsnvidia-cudnn-cu13nvidia-cusparselt-cu13nvidia-nccl-cu13nvidia-nvshmem-cu13tritonoptreeopt-einsumpyyaml;
API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/pypi/torch
More from pypi
boto3packagingcertifiurllib3requestsidna
Browse all pypi packages →

Last updated · 2026-05-13T14:55:53.234568Z

DepScope

Package intelligence for AI agents. 19 ecosystems.

Resources
API DocumentationHallucination BenchmarkFor EnterpriseSwagger / OpenAPIPopular PackagesCoverageAI Plugin SetupWatch the pitch (60s)
Legal
Legal hubPrivacy PolicyTerms of ServiceCookie PolicyAcceptable UseAttributionDPASub-processorsSecurityImprintContact中文
© 2026 Cuttalo srl — Italy · VAT IT03242390734Built for AI agents