numpy is vulnerable to Heap Buffer Overflow
31
Low Risk
Affected versions of this package are vulnerable to a heap buffer overflow when calling numpy.strings.find on specific strings. The issue stems from an incorrect multiplication by sizeof(npy_ucs4), which leads to improper memory allocation and potential out-of-bounds access. This flaw can result in application crashes or could potentially be exploited to achieve arbitrary code execution.
You are affected if you are using a version that falls within the vulnerable range.
numpy is vulnerable to Heap Buffer Overflow in versions 2.2.0 - 2.2.5.
Upgrade the numpy library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant