CVE-2020-15194
Python vulnerability analysis and mitigation

Overview

CVE-2020-15194 is a vulnerability in TensorFlow's SparseFillEmptyRowsGrad implementation that was disclosed on September 24, 2020. The vulnerability stems from incomplete validation of argument shapes, affecting TensorFlow versions prior to 2.3.0 (GitHub Advisory).

Technical details

The vulnerability exists in the SparseFillEmptyRowsGrad implementation where only reverse_index_map_t is validated to be of proper shape, while grad_values_t is accessed without proper shape validation. This occurs in the tensorflow/tensorflow/core/kernels/sparse_fill_empty_rows_op.cc file (GitHub Commit).

Impact

The vulnerability can allow malicious users to pass malformed grad_values_t parameters to trigger an assertion failure in the vec function, potentially causing denial of service in serving installations (GitHub Advisory).

Exploitability

The vulnerability can be exploited by passing a bad grad_values_t parameter to the SparseFillEmptyRowsGrad operation. This is a variant of another vulnerability (GHSA-63xm-rx5p-xvqr) (GitHub Advisory).

Mitigation and workarounds

The issue was patched in TensorFlow versions 1.15.4, 2.0.3, 2.1.2, 2.2.1, and 2.3.1. Users are recommended to upgrade to these patched versions. The fix includes proper validation of the grad_values shape (GitHub Release).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84366HIGH7.4
  • Python logoPython
  • scrapy
NoYesSep 01, 2026
CVE-2026-53720MEDIUM5.1
  • Python logoPython
  • pymonocypher
NoYesSep 03, 2026
CVE-2026-84311MEDIUM4.8
  • Python logoPython
  • pypdf
NoYesSep 01, 2026
CVE-2026-84310MEDIUM4.8
  • Python logoPython
  • pypdf
NoYesSep 01, 2026
GHSA-wwv5-g3v4-889xLOW2.3
  • Python logoPython
  • tornado
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management