Lucene search

K
osvGoogleOSV:GHSA-9FQ2-X9R6-WFMF
HistoryMay 24, 2022 - 10:00 p.m.

Numpy Deserialization of Untrusted Data

2022-05-2422:00:57
Google
osv.dev
15

0.034 Low

EPSS

Percentile

91.5%

DISPUTED An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. NOTE: third parties dispute this issue because it is a behavior that might have legitimate applications in (for example) loading serialized Python object arrays from trusted and authenticated sources.

Rows per page:
1-10 of 591