GHSA-6p56-wp2h-9hxr · Severity: medium · Ecosystem: pip — NumPy Buffer Overflow (Disputed)
A Buffer Overflow vulnerability exists in NumPy 1.9.x in the PyArray_NewFromDescr_int function of ctors.c when specifying arrays of large dimensions (over 32) from Python code, which could let a malicious user cause a Denial of Service. NOTE: The vendor does not agree this is a vulneraility; In (very limited) circumstances a user may be able provoke the buffer overflow, the user is most likely already privileged to at least provoke denial of service by exhausting memory. Triggering this further requires the use of uncommon API (complicated structured dtypes), which is very unlikely to be available to an unprivileged user
Conclusion & alert: CVE-2021-33430 is rated Exploit Available (58.3/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.07%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.17% | 1.07% | +0.90% |
| 2 | 2026-03-20 | 0.59% | 0.17% | -0.42% |
| 3 | 2025-12-10 | — | 0.59% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 3.1 | MEDIUM |
|
1.6 | 3.6 | [email protected] |
| 3.5 | 2.0 | LOW |
|
6.8 | 2.9 | [email protected] |
GHSA-6p56-wp2h-9hxr · Severity: medium · Ecosystem: pip — NumPy Buffer Overflow (Disputed)
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2021-33430 not yet assigned priority: Debian including 1 source packages (numpy), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 4, open 1. | https://security-tracker.debian.org/tracker/CVE-2021-33430 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2021-33430 |
suse
|
high | CVE-2021-33430 severity important: SUSE including 301 source package names (1.1.1.0.1.5.568:python3-numpy-1.17.3-10.1, 1.2.0.0.1.5.583:python3-numpy-1.17.3-10.1, …), 468 product×package rows across 51 product lines (Container ses/6/cephcsi/cephcsi, Container ses/6/rook/ceph, … (51 product lines)): Fixed 233, Known Affected 231, Known Not Affected 4. | https://www.suse.com/security/cve/CVE-2021-33430/ |
ubuntu
|
medium | CVE-2021-33430 medium priority: Ubuntu including 1 source packages (numpy), 8 status rows across 8 suites (focal, hirsute, impish, jammy, kinetic, trusty, upstream, xenial): ignored 4, not-affected 2, released 2. | https://ubuntu.com/security/CVE-2021-33430 |
| URL | Tags |
|---|---|
| https://github.com/numpy/numpy/issues/18939 | Exploit Third Party Advisory |