Lucene search

K
osvGoogleOSV:GHSA-FRGW-FGH6-9G52
HistoryMay 13, 2022 - 1:42 a.m.

Numpy missing input validation

2022-05-1301:42:46
Google
osv.dev
9
numpy
pad function
input validation
security
dos attack

EPSS

0.002

Percentile

54.1%

The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.