cbor2 is vulnerable to Insufficient Resource Pool
50
Medium Risk
Affected versions of this package are vulnerable to an insufficient resource pool, triggered by a MemoryError when decoding large definite strings. Exploiting this flaw could lead to a system crash and makes your system vulnerable to Denial of Service (DoS) attacks.
You are affected if you are using a version that falls within the vulnerable range.
cbor2 is vulnerable to Insufficient Resource Pool in versions 1.0.0 - 5.5.1.
Upgrade the cbor2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant