Technology · PyPI
numpy (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 9 vulnerabilities in numpy (PyPI): 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2019-6446, was published on 24 May 2022.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 1
- Exploited in the wild
- 0
About numpy (PyPI)
A fundamental package for scientific computing with Python, providing support for large, multi-dimensional arrays and matrices.
Latest numpy (PyPI) vulnerabilities
- CVE-2019-6446: NumPy insecure deserialization in numpy.loadcriticalCVSS 9.8EPSS 17.5%
- CVE-2021-41495: PYSEC-2021-856 - Null Pointer Dereference vulnerability exists in numpy.sort in NumPy < and 1.19 in the PyArray_DescrNew…lowCVSS 3.1EPSS 1.1%
- CVE-2021-41496: PYSEC-2021-857 - Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows…lowCVSS 3.1EPSS 0.4%
- CVE-2021-33430: PYSEC-2021-854 - A Buffer Overflow vulnerability exists in NumPy 1.9.x in the PyArray_NewFromDescr_int function of ctors.c…lowCVSS 3.1EPSS 1.1%
- CVE-2021-34141: PYSEC-2021-855 - Incomplete string comparison in the numpy.core component in NumPy1.9.x, which allows attackers to fail…lowCVSS 3.1EPSS 1.6%
- PYSEC-2019-38 - ** DISPUTED ** An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which…info
- CVE-2014-1859: PYSEC-2018-34 - (1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4)…lowCVSS 3EPSS 0.5%
- CVE-2014-1858: PYSEC-2018-33 - __init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink…lowCVSS 3EPSS 0.4%
- CVE-2017-12852: PYSEC-2017-1 - The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or…lowCVSS 3EPSS 2.7%
Most severe numpy (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2019-6446: NumPy insecure deserialization in numpy.loadcriticalCVSS 9.8EPSS 17.5%
- CVE-2021-34141: PYSEC-2021-855 - Incomplete string comparison in the numpy.core component in NumPy1.9.x, which allows attackers to fail…lowCVSS 3.1EPSS 1.6%
- CVE-2021-41495: PYSEC-2021-856 - Null Pointer Dereference vulnerability exists in numpy.sort in NumPy < and 1.19 in the PyArray_DescrNew…lowCVSS 3.1EPSS 1.1%
- CVE-2021-33430: PYSEC-2021-854 - A Buffer Overflow vulnerability exists in NumPy 1.9.x in the PyArray_NewFromDescr_int function of ctors.c…lowCVSS 3.1EPSS 1.1%
- CVE-2021-41496: PYSEC-2021-857 - Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows…lowCVSS 3.1EPSS 0.4%
- CVE-2017-12852: PYSEC-2017-1 - The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or…lowCVSS 3EPSS 2.7%
- CVE-2014-1859: PYSEC-2018-34 - (1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4)…lowCVSS 3EPSS 0.5%
- CVE-2014-1858: PYSEC-2018-33 - __init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink…lowCVSS 3EPSS 0.4%
- PYSEC-2019-38 - ** DISPUTED ** An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which…info
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/numpy.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "numpy (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/numpy, 28 September 2026.