Blosc maintains a small, focused compression library that sits within the data-processing pipelines of scientific computing and analytics applications, giving its vulnerabilities outsized potential impact across downstream consumers. The vendor's disclosures skew strongly toward critical-severity outcomes and concentrate in its C-Blosc2 product around memory-safety weakness classes including NULL-pointer dereferences, heap-based buffer overflows, and out-of-bounds writes, issues endemic to compression codecs that parse and manipulate binary data at scale. Defenders should prioritize this vendor's security updates for any system using embedded or bundled compression, since remediation often requires rebuilding dependent applications; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blosc over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3203CRITICAL A vulnerability, which was classified as critical, was found in c-blosc2 up to 2.13.2. Affected is the function ndlz8_decompress of the file /src/c-blosc2/plugins/codecs/ndlz/ndlz8 | Apr 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-3204CRITICAL A vulnerability has been found in c-blosc2 up to 2.13.2 and classified as critical. Affected by this vulnerability is the function ndlz4_decompress of the file /src/c-blosc2/plugin | Apr 2, 2024 | 9.8 | 24 | NO | NO |
CVE-2020-29367HIGH blosc2.c in Blosc C-Blosc2 through 2.0.0.beta.5 has a heap-based buffer overflow when there is a lack of space to write compressed data. | Nov 27, 2020 | 7.8 | 24 | NO | NO |
CVE-2023-37188HIGH C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_rate_decompress at zfp/blosc2-zfp.c. | Dec 25, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-37187HIGH C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the zfp/blosc2-zfp.c zfp_acc_decompress. function. | Dec 25, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-37185HIGH C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_prec_decompress at zfp/blosc2-zfp.c. | Dec 25, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-37186HIGH C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference in ndlz/ndlz8x8.c via a NULL pointer to memset. | Dec 25, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blosc.
Media articles that mention a CVE ID that affects a product developed by Blosc — matched by CVE ID, not by vendor name.