Feed/CVE-2019-6446
CVE-2019-6446CRITICALCVSS 9.8

Numpy Deserialization of Untrusted Data

Published May 24, 2022·Updated Jul 6, 2026

NVD Description

** DISPUTED ** An issue was discovered in NumPy 1.16.2 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. NOTE: third parties dispute this issue because it is a behavior that might have legitimate applications in (for example) loading serialized Python object arrays from trusted and authenticated sources.

Affected Packages (1)

numpyPYPI
Fixed in 1.16.3

Public Exploits & PoCs1 found

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free