GHSA-5545-2q6w-2gh6 · Severity: high · Ecosystem: pip — NumPy NULL Pointer Dereference
Null Pointer Dereference vulnerability exists in numpy.sort in NumPy < and 1.19 in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attacks by repetitively creating sort arrays. NOTE: While correct that validation is missing, an error can only occur due to an exhaustion of memory. If the user can exhaust memory, they are already privileged. Further, it should be practically impossible to construct an attack which can target the memory exhaustion to occur at exactly this place
Conclusion & alert: CVE-2021-41495 is rated Exploit Available (59.2/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.15%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.05% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.11% | 1.15% | +1.05% |
| 2 | 2025-11-21 | 0.25% | 0.11% | -0.15% |
| 3 | 2025-11-18 | — | 0.25% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 3.1 | MEDIUM |
|
1.6 | 3.6 | [email protected] |
| 3.5 | 2.0 | LOW |
|
6.8 | 2.9 | [email protected] |
GHSA-5545-2q6w-2gh6 · Severity: high · Ecosystem: pip — NumPy NULL Pointer Dereference
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2021-41495 unimportant priority: Debian including 1 source packages (numpy), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 5. | https://security-tracker.debian.org/tracker/CVE-2021-41495 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2021-41495 |
suse
|
medium | — | https://www.suse.com/security/cve/CVE-2021-41495/ |
ubuntu
|
medium | CVE-2021-41495 medium priority: Ubuntu including 1 source packages (numpy), 9 status rows across 9 suites (focal, hirsute, impish, jammy, kinetic, lunar, trusty, upstream, xenial): ignored 4, released 4, not-affected 1. | https://ubuntu.com/security/CVE-2021-41495 |
| URL | Tags |
|---|---|
| https://github.com/numpy/numpy/issues/19038 | Exploit Issue Tracking Third Party Advisory |
| https://www.oracle.com/security-alerts/cpujul2022.html | Third Party Advisory |