An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| numpy(PyPI) | 0 | 1.22 | N/A |
CVSS Metrics