CVE-2022-41886

Overflow in `ImageProjectiveTransformV2` in Tensorflow

TensorFlow is an open source platform for machine learning. When `tf.raw_ops.ImageProjectiveTransformV2` is given a large output shape, it overflows. We have patched the issue in GitHub commit 8faa6ea692985dbe6ce10e1a3168e0bd60a723ba. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.


We have discovered 27 live websites that are affected by CVE-2022-41886.

Run a Free Instant Scan




Affected Software

Product  tensorflow
Category JavaScript Libraries
Vulnerable Domains27 live websites (7.54% of tensorflow install base)
Vulnerable Versions
  • from 0 through 2.8.4
  • from 2.9 through 2.9.3
  • from 2.10 through 2.10.1
Vulnerable Versions Count5 versions ( 71% of all versions)


Common Weakness Enumeration

CWE-131 Incorrect Calculation of Buffer Size



Details

  • Published - Nov 18, 2022
  • Updated - Apr 22, 2025

Website Distribution by Country

Number of websites using CVE-2022-41886
United States19 websites



Germany2 websites
India2 websites
Brazil1 websites
Canada1 websites
Korea, South1 websites
Netherlands1 websites

Website Distribution by TLD

Number of websites using CVE-2022-41886
.com15 websites
.net2 websites
.com.br1 websites
.io1 websites
.org1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-41886

Top websites that are affected by CVE-2022-41886. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com United States***,***
************.com United States***,***
******.me United States*,***,***
***********.com United States*,***,***
************.com United States*,***,***
****.net United States*,***,***
***********.com United States*,***,***
*******.**.kr Korea, South*,***,***
**********.com Netherlands*,***,***
********.app United States*,***,***
See full domain list

FAQ

CVE-2022-41886 is Incorrect Calculation of Buffer Size in tensorflow
A total of 27 websites have been identified as vulnerable to CVE-2022-41886, based on global website indexing conducted by WebTechSurvey.
The tensorflow is affected by the CVE-2022-41886 vulnerability.
tensorflow versions up to 2.10.1 are vulnerable to CVE-2022-41886.
CVE-2022-41886 is resolved in version 2.10.1 of tensorflow.