VDB
Sign up

PYSEC-2023-121

zstd vulnerable to buffer overrun

Withdrawn 2025-11-07. This finding no longer applies and is kept for reference. It is not used when checking packages.

Quick fix

PYSEC-2023-121 — zstd: upgrade to the fixed version with the command below.

pip install --upgrade 'zstd>=1.5.4'

Details

A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/zstd
Introduced in: 0Fixed in: 1.5.4
Fixpip install --upgrade 'zstd>=1.5.4'

References