{"schema_version":1,"title":"numpy (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 9 vulnerabilities in numpy (PyPI): 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2019-6446, was published on 24 May 2022.","url":"https://junglewise.ai/threats/technologies/numpy","json_url":"https://junglewise.ai/threats/technologies/numpy.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/numpy","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":9,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":0},"latest":[{"cve":"CVE-2019-6446","cvss":9.8,"epss":0.1753,"slug":"cve-2019-6446-numpy-insecure-deserialization-in-numpy-load","title":"NumPy insecure deserialization in numpy.load","severity":"critical","exploited":false,"published_at":"2022-05-24T22:00:57+00:00","url":"https://junglewise.ai/threats/cve-2019-6446-numpy-insecure-deserialization-in-numpy-load"},{"cve":"CVE-2021-41495","cvss":3.1,"epss":0.0115,"slug":"cve-2021-41495-numpy-null-pointer-dereference","title":"PYSEC-2021-856 - Null Pointer Dereference vulnerability exists in numpy.sort in NumPy &lt and 1.19 in the PyArray_DescrNew function due to missing return-val","severity":"low","exploited":false,"published_at":"2021-12-17T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-41495-numpy-null-pointer-dereference"},{"cve":"CVE-2021-41496","cvss":3.1,"epss":0.0037,"slug":"cve-2021-41496-buffer-copy-without-checking-size-of-input-in-numpy","title":"PYSEC-2021-857 - Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service a","severity":"low","exploited":false,"published_at":"2021-12-17T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-41496-buffer-copy-without-checking-size-of-input-in-numpy"},{"cve":"CVE-2021-33430","cvss":3.1,"epss":0.0107,"slug":"cve-2021-33430-numpy-buffer-overflow-disputed","title":"PYSEC-2021-854 - A Buffer Overflow vulnerability exists in NumPy 1.9.x in the PyArray_NewFromDescr_int function of ctors.c when specifying arrays of large di","severity":"low","exploited":false,"published_at":"2021-12-17T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-33430-numpy-buffer-overflow-disputed"},{"cve":"CVE-2021-34141","cvss":3.1,"epss":0.0156,"slug":"cve-2021-34141-incorrect-comparison-in-numpy","title":"PYSEC-2021-855 - Incomplete string comparison in the numpy.core component in NumPy1.9.x, which allows attackers to fail the APIs via constructing specific st","severity":"low","exploited":false,"published_at":"2021-12-17T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-34141-incorrect-comparison-in-numpy"},{"slug":"pysec-2019-38-disputed-an-issue-was-discovered-in-numpy-1-16-0-and-92c3370e","title":"PYSEC-2019-38 - ** DISPUTED ** An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attacke","severity":"info","exploited":false,"published_at":"2019-01-16T05:29:00+00:00","url":"https://junglewise.ai/threats/pysec-2019-38-disputed-an-issue-was-discovered-in-numpy-1-16-0-and-92c3370e"},{"cve":"CVE-2014-1859","cvss":3,"epss":0.0047,"slug":"cve-2014-1859-numpy-arbitrary-file-write-via-symlink-attack","title":"PYSEC-2018-34 - (1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 all","severity":"low","exploited":false,"published_at":"2018-01-08T19:29:00+00:00","url":"https://junglewise.ai/threats/cve-2014-1859-numpy-arbitrary-file-write-via-symlink-attack"},{"cve":"CVE-2014-1858","cvss":3,"epss":0.0045,"slug":"cve-2014-1858-arbitrary-file-write-in-numpy","title":"PYSEC-2018-33 - __init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file.","severity":"low","exploited":false,"published_at":"2018-01-08T19:29:00+00:00","url":"https://junglewise.ai/threats/cve-2014-1858-arbitrary-file-write-in-numpy"},{"cve":"CVE-2017-12852","cvss":3,"epss":0.0272,"slug":"cve-2017-12852-numpy-missing-input-validation","title":"PYSEC-2017-1 - The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite","severity":"low","exploited":false,"published_at":"2017-08-15T16:29:00+00:00","url":"https://junglewise.ai/threats/cve-2017-12852-numpy-missing-input-validation"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"numpy (PyPI)","slug":"numpy","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://numpy.org/","repo_url":"https://github.com/numpy/numpy","description":"A fundamental package for scientific computing with Python, providing support for large, multi-dimensional arrays and matrices.","url":"https://junglewise.ai/threats/technologies/numpy"},"most_severe":[{"cve":"CVE-2019-6446","cvss":9.8,"epss":0.1753,"slug":"cve-2019-6446-numpy-insecure-deserialization-in-numpy-load","title":"NumPy insecure deserialization in numpy.load","severity":"critical","exploited":false,"published_at":"2022-05-24T22:00:57+00:00","url":"https://junglewise.ai/threats/cve-2019-6446-numpy-insecure-deserialization-in-numpy-load"},{"cve":"CVE-2021-34141","cvss":3.1,"epss":0.0156,"slug":"cve-2021-34141-incorrect-comparison-in-numpy","title":"PYSEC-2021-855 - Incomplete string comparison in the numpy.core component in NumPy1.9.x, which allows attackers to fail the APIs via constructing specific st","severity":"low","exploited":false,"published_at":"2021-12-17T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-34141-incorrect-comparison-in-numpy"},{"cve":"CVE-2021-41495","cvss":3.1,"epss":0.0115,"slug":"cve-2021-41495-numpy-null-pointer-dereference","title":"PYSEC-2021-856 - Null Pointer Dereference vulnerability exists in numpy.sort in NumPy &lt and 1.19 in the PyArray_DescrNew function due to missing return-val","severity":"low","exploited":false,"published_at":"2021-12-17T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-41495-numpy-null-pointer-dereference"},{"cve":"CVE-2021-33430","cvss":3.1,"epss":0.0107,"slug":"cve-2021-33430-numpy-buffer-overflow-disputed","title":"PYSEC-2021-854 - A Buffer Overflow vulnerability exists in NumPy 1.9.x in the PyArray_NewFromDescr_int function of ctors.c when specifying arrays of large di","severity":"low","exploited":false,"published_at":"2021-12-17T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-33430-numpy-buffer-overflow-disputed"},{"cve":"CVE-2021-41496","cvss":3.1,"epss":0.0037,"slug":"cve-2021-41496-buffer-copy-without-checking-size-of-input-in-numpy","title":"PYSEC-2021-857 - Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service a","severity":"low","exploited":false,"published_at":"2021-12-17T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-41496-buffer-copy-without-checking-size-of-input-in-numpy"},{"cve":"CVE-2017-12852","cvss":3,"epss":0.0272,"slug":"cve-2017-12852-numpy-missing-input-validation","title":"PYSEC-2017-1 - The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite","severity":"low","exploited":false,"published_at":"2017-08-15T16:29:00+00:00","url":"https://junglewise.ai/threats/cve-2017-12852-numpy-missing-input-validation"},{"cve":"CVE-2014-1859","cvss":3,"epss":0.0047,"slug":"cve-2014-1859-numpy-arbitrary-file-write-via-symlink-attack","title":"PYSEC-2018-34 - (1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 all","severity":"low","exploited":false,"published_at":"2018-01-08T19:29:00+00:00","url":"https://junglewise.ai/threats/cve-2014-1859-numpy-arbitrary-file-write-via-symlink-attack"},{"cve":"CVE-2014-1858","cvss":3,"epss":0.0045,"slug":"cve-2014-1858-arbitrary-file-write-in-numpy","title":"PYSEC-2018-33 - __init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file.","severity":"low","exploited":false,"published_at":"2018-01-08T19:29:00+00:00","url":"https://junglewise.ai/threats/cve-2014-1858-arbitrary-file-write-in-numpy"},{"slug":"pysec-2019-38-disputed-an-issue-was-discovered-in-numpy-1-16-0-and-92c3370e","title":"PYSEC-2019-38 - ** DISPUTED ** An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attacke","severity":"info","exploited":false,"published_at":"2019-01-16T05:29:00+00:00","url":"https://junglewise.ai/threats/pysec-2019-38-disputed-an-issue-was-discovered-in-numpy-1-16-0-and-92c3370e"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}