CVE-2026-44484 Details
Description
PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.
A security incident has been identified in the PyTorch Lightning package versions 2.6.2 and 2.6.3, where released versions have been compromised to include malicious code consistent with a credential harvesting mechanism. The root cause of this compromise is still under investigation.
Users are advised to delete the compromised versions 2.6.2 and 2.6.3 from their systems, pin PyTorch Lightning to version 2.6.1, and rotate all credentials and secrets that may have been exposed. After removing the compromised versions, rebuild affected systems from a known clean state.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-44484 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2477476 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44484.json | redhat-SADP | |
| https://github.com/Lightning-AI/pytorch-lightning/security/advisories/GHSA-w37p-236h-pfx3 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-506 | Embedded Malicious Code | [email protected] |
| CWE-829 | Inclusion of Functionality from Untrusted Control Sphere | redhat-SADP |
Affected Products
| Product | Versions |
|---|---|
| lightningai pytorch lightning | 2.6.2 2.6.3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 21, 2026 | Initial Analysis | [email protected] |
| May 14, 2026 | New CVE Received | [email protected] |