HIGH
GHSA-94vc-p8w7-5p49
Bundled libwebp in imagecodecs vulnerable
Quick fix
GHSA-94vc-p8w7-5p49 — imagecodecs: upgrade to the fixed version with the command below.
pip install --upgrade 'imagecodecs>=2023.9.18'Details
imagecodecs versions before v2023.9.18 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-5129 (previously CVE-2023-4863). imagecodecs v2023.9.18 upgrades the bundled libwebp binary to v1.3.2.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/imagecodecs
Introduced in:
0Fixed in: 2023.9.18Fix
pip install --upgrade 'imagecodecs>=2023.9.18'References
- https://nvd.nist.gov/vuln/detail/CVE-2023-4863[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2023-5129[ADVISORY]
- https://github.com/cgohlke/imagecodecs[PACKAGE]
- https://github.com/cgohlke/imagecodecs/blob/v2023.9.18/CHANGES.rst[WEB]
- https://github.com/pypa/advisory-database/tree/main/vulns/imagecodecs/PYSEC-2023-174.yaml[WEB]