{"schema_version":1,"title":"lief (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 11 vulnerabilities in lief (PyPI): 0 in the last 7 days and 1 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-15504, was published on 7 July 2026.","url":"https://junglewise.ai/threats/technologies/lief","json_url":"https://junglewise.ai/threats/technologies/lief.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/lief","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":11,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":1,"last_365_days":1},"latest":[{"cve":"CVE-2025-15504","cvss":3.1,"epss":0.0027,"slug":"cve-2025-15504-lief-is-vulnerable-to-segmentation-fault","title":"PYSEC-2026-1538 - LIEF is vulnerable to segmentation fault","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:17.881535+00:00","url":"https://junglewise.ai/threats/cve-2025-15504-lief-is-vulnerable-to-segmentation-fault"},{"cve":"CVE-2024-31636","cvss":3.9,"epss":0.0024,"slug":"cve-2024-31636-lief-uninitialized-variable-in-machd-reader-c","title":"LIEF uninitialized variable in machd_reader.c","severity":"low","exploited":false,"published_at":"2024-05-03T18:30:37+00:00","url":"https://junglewise.ai/threats/cve-2024-31636-lief-uninitialized-variable-in-machd-reader-c"},{"cve":"CVE-2022-43171","cvss":3.1,"epss":0.0069,"slug":"cve-2022-43171-lief-heap-buffer-overflow-in-the-lief-macho-binaryparser-parse","title":"PYSEC-2022-43140 - A heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bind function of LIEF v0.12.1 allows attackers to cause a De","severity":"low","exploited":false,"published_at":"2022-11-17T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-43171-lief-heap-buffer-overflow-in-the-lief-macho-binaryparser-parse"},{"cve":"CVE-2022-40922","cvss":3.1,"epss":0.0063,"slug":"cve-2022-40922-lief-segmentation-fault-in-macho-binary-parser","title":"PYSEC-2022-43138 - A vulnerability in the LIEF::MachO::BinaryParser::init_and_parse function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS","severity":"low","exploited":false,"published_at":"2022-10-03T13:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-40922-lief-segmentation-fault-in-macho-binary-parser"},{"cve":"CVE-2022-40923","cvss":3.1,"epss":0.0065,"slug":"cve-2022-40923-lief-vulnerable-to-denial-of-service-through-segmentation-fault","title":"PYSEC-2022-43139 - A vulnerability in the LIEF::MachO::SegmentCommand::virtual_address function of LIEF v0.12.1 allows attackers to cause a denial of service (","severity":"low","exploited":false,"published_at":"2022-09-30T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-40923-lief-vulnerable-to-denial-of-service-through-segmentation-fault"},{"cve":"CVE-2022-38496","cvss":3.1,"epss":0.003,"slug":"cve-2022-38496-pysec-2022-43137-lief-commit-365a16a-was-discovered-to-contain-a","title":"PYSEC-2022-43137 - LIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp.","severity":"low","exploited":false,"published_at":"2022-09-13T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-38496-pysec-2022-43137-lief-commit-365a16a-was-discovered-to-contain-a"},{"cve":"CVE-2022-38495","cvss":3.1,"epss":0.0034,"slug":"cve-2022-38495-lief-vulnerable-to-heap-based-buffer-overflow-via-print-binary","title":"PYSEC-2022-276 - LIEF commit 365a16a was discovered to contain a heap-buffer overflow via the function print_binary at /c/macho_reader.c.","severity":"low","exploited":false,"published_at":"2022-09-13T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-38495-lief-vulnerable-to-heap-based-buffer-overflow-via-print-binary"},{"cve":"CVE-2022-38306","cvss":3.1,"epss":0.0034,"slug":"cve-2022-38306-lief-vulnerable-to-heap-based-buffer-overflow","title":"PYSEC-2022-274 - LIEF commit 5d1d643 was discovered to contain a heap-buffer overflow in the component /core/CorePrPsInfo.tcc.","severity":"low","exploited":false,"published_at":"2022-09-13T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-38306-lief-vulnerable-to-heap-based-buffer-overflow"},{"cve":"CVE-2022-38307","cvss":3.1,"epss":0.003,"slug":"cve-2022-38307-lief-contains-segmentation-violation","title":"PYSEC-2022-275 - LIEF commit 5d1d643 was discovered to contain a segmentation violation via the function LIEF::MachO::SegmentCommand::file_offset() at /MachO","severity":"low","exploited":false,"published_at":"2022-09-13T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-38307-lief-contains-segmentation-violation"},{"cve":"CVE-2022-38497","cvss":3.1,"epss":0.003,"slug":"cve-2022-38497-lief-null-pointer-dereference-in-elf-corefile-parsing","title":"PYSEC-2022-277 - LIEF commit 365a16a was discovered to contain a segmentation violation via the component CoreFile.tcc:69.","severity":"low","exploited":false,"published_at":"2022-09-13T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-38497-lief-null-pointer-dereference-in-elf-corefile-parsing"},{"cve":"CVE-2021-32297","cvss":3.1,"epss":0.0156,"slug":"cve-2021-32297-lief-heap-buffer-overflow-in-pe-parsing","title":"PYSEC-2021-324 - An issue was discovered in LIEF through 0.11.4. A heap-buffer-overflow exists in the function main located in pe_reader.c. It allows an atta","severity":"low","exploited":false,"published_at":"2021-09-20T16:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-32297-lief-heap-buffer-overflow-in-pe-parsing"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"lief (PyPI)","slug":"lief","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://lief-project.github.io/","repo_url":"https://github.com/lief-project/LIEF","description":"A library for parsing, modifying, and abstracting executable formats including ELF, PE, Mach-O, and Android formats.","url":"https://junglewise.ai/threats/technologies/lief"},"most_severe":[{"cve":"CVE-2024-31636","cvss":3.9,"epss":0.0024,"slug":"cve-2024-31636-lief-uninitialized-variable-in-machd-reader-c","title":"LIEF uninitialized variable in machd_reader.c","severity":"low","exploited":false,"published_at":"2024-05-03T18:30:37+00:00","url":"https://junglewise.ai/threats/cve-2024-31636-lief-uninitialized-variable-in-machd-reader-c"},{"cve":"CVE-2021-32297","cvss":3.1,"epss":0.0156,"slug":"cve-2021-32297-lief-heap-buffer-overflow-in-pe-parsing","title":"PYSEC-2021-324 - An issue was discovered in LIEF through 0.11.4. A heap-buffer-overflow exists in the function main located in pe_reader.c. It allows an atta","severity":"low","exploited":false,"published_at":"2021-09-20T16:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-32297-lief-heap-buffer-overflow-in-pe-parsing"},{"cve":"CVE-2022-43171","cvss":3.1,"epss":0.0069,"slug":"cve-2022-43171-lief-heap-buffer-overflow-in-the-lief-macho-binaryparser-parse","title":"PYSEC-2022-43140 - A heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bind function of LIEF v0.12.1 allows attackers to cause a De","severity":"low","exploited":false,"published_at":"2022-11-17T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-43171-lief-heap-buffer-overflow-in-the-lief-macho-binaryparser-parse"},{"cve":"CVE-2022-40923","cvss":3.1,"epss":0.0065,"slug":"cve-2022-40923-lief-vulnerable-to-denial-of-service-through-segmentation-fault","title":"PYSEC-2022-43139 - A vulnerability in the LIEF::MachO::SegmentCommand::virtual_address function of LIEF v0.12.1 allows attackers to cause a denial of service (","severity":"low","exploited":false,"published_at":"2022-09-30T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-40923-lief-vulnerable-to-denial-of-service-through-segmentation-fault"},{"cve":"CVE-2022-40922","cvss":3.1,"epss":0.0063,"slug":"cve-2022-40922-lief-segmentation-fault-in-macho-binary-parser","title":"PYSEC-2022-43138 - A vulnerability in the LIEF::MachO::BinaryParser::init_and_parse function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS","severity":"low","exploited":false,"published_at":"2022-10-03T13:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-40922-lief-segmentation-fault-in-macho-binary-parser"},{"cve":"CVE-2022-38495","cvss":3.1,"epss":0.0034,"slug":"cve-2022-38495-lief-vulnerable-to-heap-based-buffer-overflow-via-print-binary","title":"PYSEC-2022-276 - LIEF commit 365a16a was discovered to contain a heap-buffer overflow via the function print_binary at /c/macho_reader.c.","severity":"low","exploited":false,"published_at":"2022-09-13T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-38495-lief-vulnerable-to-heap-based-buffer-overflow-via-print-binary"},{"cve":"CVE-2022-38306","cvss":3.1,"epss":0.0034,"slug":"cve-2022-38306-lief-vulnerable-to-heap-based-buffer-overflow","title":"PYSEC-2022-274 - LIEF commit 5d1d643 was discovered to contain a heap-buffer overflow in the component /core/CorePrPsInfo.tcc.","severity":"low","exploited":false,"published_at":"2022-09-13T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-38306-lief-vulnerable-to-heap-based-buffer-overflow"},{"cve":"CVE-2022-38497","cvss":3.1,"epss":0.003,"slug":"cve-2022-38497-lief-null-pointer-dereference-in-elf-corefile-parsing","title":"PYSEC-2022-277 - LIEF commit 365a16a was discovered to contain a segmentation violation via the component CoreFile.tcc:69.","severity":"low","exploited":false,"published_at":"2022-09-13T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-38497-lief-null-pointer-dereference-in-elf-corefile-parsing"},{"cve":"CVE-2022-38496","cvss":3.1,"epss":0.003,"slug":"cve-2022-38496-pysec-2022-43137-lief-commit-365a16a-was-discovered-to-contain-a","title":"PYSEC-2022-43137 - LIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp.","severity":"low","exploited":false,"published_at":"2022-09-13T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-38496-pysec-2022-43137-lief-commit-365a16a-was-discovered-to-contain-a"},{"cve":"CVE-2022-38307","cvss":3.1,"epss":0.003,"slug":"cve-2022-38307-lief-contains-segmentation-violation","title":"PYSEC-2022-275 - LIEF commit 5d1d643 was discovered to contain a segmentation violation via the function LIEF::MachO::SegmentCommand::file_offset() at /MachO","severity":"low","exploited":false,"published_at":"2022-09-13T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-38307-lief-contains-segmentation-violation"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}