SciPy is a widely used Python scientific-computing library that, despite a narrow product scope, is embedded across research, data analysis, and machine-learning workflows where it provides numerical algorithms and statistical functions. Its observed vulnerability classes—including improper privilege management, memory-safety issues such as use-after-free and memory leaks, and other implementation flaws—reflect the complexity of C-based numerical code and the interface boundary between Python and native extensions. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scipy over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-29824CRITICAL A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor and discoverer indicate that this is not a security issue. | Jul 6, 2023 | 9.8 | 31 | NO | NO |
CVE-2013-4251HIGH The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories. | Nov 4, 2019 | 7.8 | 20 | NO | NO |
CVE-2023-25399MEDIUM A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. Note: This is disputed as a bug and not a vulnerabi | Jul 5, 2023 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scipy.
Media articles that mention a CVE ID that affects a product developed by Scipy — matched by CVE ID, not by vendor name.