Joblib is a lightweight Python serialization and parallel computing library widely embedded in data science and machine learning workflows, where its narrow product scope belies broad downstream integration across research and production environments. The observed vulnerability exposure centers on deserialization of untrusted data and code-injection mechanisms inherent to the library's core functionality for task caching and distributed execution. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joblib Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-21797CRITICAL The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement. | Sep 26, 2022 | 9.8 | 32 | NO | NO |
CVE-2024-34997HIGH joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array(). NOTE: this is disputed by the suppl | May 17, 2024 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joblib Project.
Media articles that mention a CVE ID that affects a product developed by Joblib Project — matched by CVE ID, not by vendor name.