# ShellTorch Patch Availability

**URL:** https://dev-discuss.pytorch.org/t/shelltorch-patch-availability/1541
**Category:** release/packaging
**Created:** [October 5, 2023, 3:17pm UTC](https://dev-discuss.pytorch.org/t/shelltorch-patch-availability/1541 "2023-10-05T15:17:16Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![bmonroe](https://avatars.discourse-cdn.com/v4/letter/b/c37758/32.png) [@bmonroe](https://dev-discuss.pytorch.org/u/bmonroe)
#### Post date: [October 5, 2023, 3:17pm UTC](https://dev-discuss.pytorch.org/t/shelltorch-patch-availability/1541/1 "2023-10-05T15:17:16Z")

</div>

Can you share if there is a new release planned to address the ShellTorch vulnerabilities and if so the timing? We are working to address these vulnerabilities but for the SSRF issue, v0.8.2 just does a warning. We don’t want to patch twice if at all possible.

References:

> **[ShellTorch: Multiple Critical Vulnerabilities in PyTorch Model Server...](https://www.oligo.security/blog/shelltorch-torchserve-ssrf-vulnerability-cve-2023-43654)**
>
> Oligo unveils ShellTorch: critical vulnerabilities in TorchServe (PyTorch Model Server), including CVE-2023-43654 (SSRF) & CVE-2022-1471 (RCE), threaten AI users.

ShellTorch page: [ShellTorch: Critical Vulnerabilities in TorchServe (including CVE-2023-43654)](https://www.oligo.security/shelltorch)

ShellTorchCheker: [GitHub - OligoCyberSecurity/ShellTorchChecker: A tool that checks if a TorchServe instance is vulnerable to CVE-2023-43654](https://github.com/OligoCyberSecurity/ShellTorchChecker)

AWS advisory: [Reported TorchServe Issue (CVE-2023-43654)](https://aws.amazon.com/security/security-bulletins/AWS-2023-009/)

B/R  
Bruce

---

<div class="post-metadata">

### Author: ![msaroufim](https://yyz2.discourse-cdn.com/flex036/user_avatar/dev-discuss.pytorch.org/msaroufim/32/489_2.png) [@msaroufim](https://dev-discuss.pytorch.org/u/msaroufim)
#### Post date: [October 5, 2023, 6:37pm UTC](https://dev-discuss.pytorch.org/t/shelltorch-patch-availability/1541/2 "2023-10-05T18:37:44Z")

</div>

Hi torchserve developer here!

They blogged about issues only affect torchserve not PyTorch and all the major issues they’ve listed out have been patched in 0.8.2

Regarding the “just a warning part” the blog was referring to some documentation changes that were missing, we’ve since made them. Doc changes don’t require a release but we are indeed planning another release 0.9.0 before Oct 15

1. Advise on how to secure torchserve when dealing with docker: [updates to security guidelines and docker config by agunapal · Pull Request #2669 · pytorch/serve · GitHub](https://github.com/pytorch/serve/pull/2669)
2. In our docker examples we no longer use 0.0.0.0 [Bind torchserve container ports to localhost ports by namannandan · Pull Request #2646 · pytorch/serve · GitHub](https://github.com/pytorch/serve/pull/2646)
3. In our documentation we no longer use 0.0.0.0 [Update default address from 0.0.0.0 to 127.0.0.1 in documentation and examples by namannandan · Pull Request #2624 · pytorch/serve · GitHub](https://github.com/pytorch/serve/pull/2624)
4. We’re now recommending people use 0.8.2 for the latest security patches [Update SECURITY.md by msaroufim · Pull Request #2643 · pytorch/serve · GitHub](https://github.com/pytorch/serve/pull/2643)

Also we have since proactively fixed many more security issues which you can follow by checking for the `security` tag on github [Pull requests · pytorch/serve · GitHub](https://github.com/pytorch/serve/pulls?q=is%3Apr+is%3Amerged+label%3Asecurity+)

We take security very seriously on the team by including tools for code scanning and regular dependency upgrades and we list out our approach here [https://github.com/pytorch/serve/blob/master/SECURITY.md](https://github.com/pytorch/serve/blob/master/SECURITY.md)

---

<div class="post-metadata">

### Author: ![bmonroe](https://avatars.discourse-cdn.com/v4/letter/b/c37758/32.png) [@bmonroe](https://dev-discuss.pytorch.org/u/bmonroe)
#### Post date: [October 5, 2023, 6:55pm UTC](https://dev-discuss.pytorch.org/t/shelltorch-patch-availability/1541/3 "2023-10-05T18:55:29Z")

</div>

Hi Mark,

Thank you for closing the loop. I’ll pass this along to the team we have working this response effort internally.

Best Regards,

Bruce

_Bruce Monroe_

_PE/Lead Engineer High Profile Response Events_

_Intel Product Security Incident Response Team_

_Web: [www.intel.com/security](http://www.intel.com/security)_

_PSIRT Email: [secure@intel.com](mailto:secure@intel.com)_

_Full Remote/East Coast Time Zone_

[![](https://canada1.discourse-cdn.com/flex036/uploads/pytorch1/original/2X/1/1b2e173368b183367767d13eac261f1862dcebe1.png)](https://www.intel.com/content/www/us/en/security/product-security-assurance.html)
