StackRadar

CVE-2021-41496

Medium

Advisory

Published 17 Dec 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
27
of 17,781 indexed, latest versions
Container images
26
deployed by those charts
Fix available
2 of 2
affected packages

Buffer Copy without Checking Size of Input in NumPy

Carried by container images the latest versions of 27 of 17,781 indexed charts deploy, on 26 images.

Affected packageAffected versionsFixed inImages
numpypypi1.7.1, 1.9.2, 1.14.1, 1.14.3+8 more1.1922
numpydeb1:1.17.4-5ubuntu3, 1:1.24.2-1+deb12u1, 1:2.2.4+ds-11:1.17.4-5ubuntu3.19
OSV records
DEBIAN-CVE-2021-41496GHSA-f7c7-j99h-c22fUBUNTU-CVE-2021-41496
Also known as
PYSEC-2021-857, USN-5763-1

Charts affected

27 by stars
ChartLatestAffected imagesRadar Score
supersetcloudposse1.2.01 of 1See more

superset cloudposse 1.2.0

1 of the 1 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
numpy@1.17.0
1.19

Open the chart page →

5,851
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
numpy@1.17.0
1.19

Open the chart page →

52,919
deconzgeek-cookbookVerified publisher6.5.21 of 1See more

deconz geek-cookbook 6.5.2

1 of the 1 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.12.066541bbb78952
numpy@1.16.2
1.19

Open the chart page →

3,555
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
numpy@1:1.17.4-5ubuntu3
numpy@1.17.4
1:1.17.4-5ubuntu3.1
1.19

Open the chart page →

10,598
open-elevationbeeinventor0.1.01 of 2See more

open-elevation beeinventor 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
openelevation/open-elevation:latest82fb21612e86
numpy@1:1.17.4-5ubuntu3
numpy@1.17.4
1:1.17.4-5ubuntu3.1
1.19

Open the chart page →

13,145
tensorflow-notebookcloudnativeapp0.1.21 of 1See more

tensorflow-notebook cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
tensorflow/tensorflow:1.6.0-devel1e3172090703
numpy@1.14.1
1.19

Open the chart page →

36,094
smarter-demosmarterOfficialVerified publisher0.1.52 of 7See more

smarter-demo smarter 0.1.5

2 of the 7 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
numpy@1:1.17.4-5ubuntu3
numpy@1.17.4
1:1.17.4-5ubuntu3.1
1.19
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
numpy@1:1.17.4-5ubuntu3
numpy@1.17.4
1:1.17.4-5ubuntu3.1
1.19

Open the chart page →

45,832
radosgwananace-chartsVerified publisher0.3.41 of 1See more

radosgw ananace-charts 0.3.4

1 of the 1 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
ceph/daemon:latest-nautilus90f30824a96e
numpy@1.7.1
1.19

Open the chart page →

1,650
daskcloudnativeapp2.2.12 of 2See more

dask cloudnativeapp 2.2.1

2 of the 2 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
daskdev/dask:1.1.04ecd7bc35500
numpy@1.15.4
1.19
daskdev/dask-notebook:1.1.0052630f5ca04
numpy@1.15.4
1.19

Open the chart page →

29,901
distributed-tensorflowcloudnativeapp0.1.11 of 1See more

distributed-tensorflow cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
cheyang/distributed-tf:1.6.046cc34755493
numpy@1.14.1
1.19

Open the chart page →

36,094
supersetcloudnativeapp1.1.61 of 1See more

superset cloudnativeapp 1.1.6

1 of the 1 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
amancevice/superset:0.28.1c8c04bfe3d66
numpy@1.15.2
1.19

Open the chart page →

5,060
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
numpy@1.9.2
1.19

Open the chart page →

70,895
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
numpy@1.16.2
1.19

Open the chart page →

27,728
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
numpy@1.16.2
1.19

Open the chart page →

22,405
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
numpy@1.16.2
1.19

Open the chart page →

24,335
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
numpy@1:2.2.4+ds-1
no fix listed

Open the chart page →

7,459
spark-standalonedmwm-bigdataVerified publisher0.1.01 of 2See more

spark-standalone dmwm-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
numpy@1.16.4
1.19

Open the chart page →

6,147
spark-standalonegradiant-bigdataVerified publisher0.1.01 of 2See more

spark-standalone gradiant-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
numpy@1.16.4
1.19

Open the chart page →

6,147
itm-servicesintelVerified publisher2.0.01 of 8See more

itm-services intel 2.0.0

1 of the 8 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
numpy@1:1.17.4-5ubuntu3
numpy@1.17.4
1:1.17.4-5ubuntu3.1
1.19

Open the chart page →

18,066
inventreeinventreeOfficialVerified publisher0.4.281 of 2See more

inventree inventree 0.4.28

1 of the 2 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
inventree/inventree:1.5.4a946ec09da3e
numpy@1:2.2.4+ds-1
no fix listed

Open the chart page →

5,788
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
numpy@1:1.24.2-1+deb12u1
no fix listed

Open the chart page →

10,780
reportportalreportportal5.7.21 of 8See more

reportportal reportportal 5.7.2

1 of the 8 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
reportportal/service-metrics-gatherer:1.1.202a0e6dc11161
numpy@1.16.4
1.19

Open the chart page →

25,737
seldon-core-loadtestingseldon0.2.01 of 1See more

seldon-core-loadtesting seldon 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
seldonio/locust-core:0.81d0da98a2d76
numpy@1.16.3
1.19

Open the chart page →

23,007
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
signalen/backend:2.50.14760256000738
numpy@1:1.24.2-1+deb12u1
no fix listed

Open the chart page →

11,636
classificationsignalen4.24.01 of 1See more

classification signalen 4.24.0

1 of the 1 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
signalen/classification:ad60447d1733473e30ab0a3ba53d58141cc1d2509496ae672877
numpy@1.18.5
1.19

Open the chart page →

1,553
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
numpy@1.14.3
1.19

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2021-41496.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
numpy@1.14.3
1.19

Open the chart page →

11,784

Container images carrying it

26 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
amancevice/superset:0.35.212a0a9e66550
numpy@1.17.0
1.19
2
gradiant/spark:2.4.4-python-alpine97657d56e927
numpy@1.16.4
1.19
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
numpy@1.14.3
1.19
2
amancevice/superset:0.28.1c8c04bfe3d66
numpy@1.15.2
1.19
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
numpy@1:1.17.4-5ubuntu3
numpy@1.17.4
1:1.17.4-5ubuntu3.1
1.19
1
ceph/daemon:latest-nautilus90f30824a96e
numpy@1.7.1
1.19
1
cheyang/distributed-tf:1.6.046cc34755493
numpy@1.14.1
1.19
1
daskdev/dask:1.1.04ecd7bc35500
numpy@1.15.4
1.19
1
daskdev/dask-notebook:1.1.0052630f5ca04
numpy@1.15.4
1.19
1
deconzcommunity/deconz:2.29.2062de2362641
numpy@1:1.24.2-1+deb12u1
no fix listed
1
deconzcommunity/deconz:2.12.066541bbb78952
numpy@1.16.2
1.19
1
galaxy/galaxy-init:v18.010267bad550e6
numpy@1.9.2
1.19
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
numpy@1:1.17.4-5ubuntu3
numpy@1.17.4
1:1.17.4-5ubuntu3.1
1.19
1
inventree/inventree:1.5.4a946ec09da3e
numpy@1:2.2.4+ds-1
no fix listed
1
opendatacube/pipelines:wofs-1.225d810e8504b8
numpy@1.16.2
1.19
1
opendatacube/restcube:latest91870111837c
numpy@1.16.2
1.19
1
opendatacube/wms:latest1b90cdf68831
numpy@1.16.2
1.19
1
openelevation/open-elevation:latest82fb21612e86
numpy@1:1.17.4-5ubuntu3
numpy@1.17.4
1:1.17.4-5ubuntu3.1
1.19
1
reportportal/service-metrics-gatherer:1.1.202a0e6dc11161
numpy@1.16.4
1.19
1
seldonio/locust-core:0.81d0da98a2d76
numpy@1.16.3
1.19
1
signalen/backend:2.50.14760256000738
numpy@1:1.24.2-1+deb12u1
no fix listed
1
signalen/classification:ad60447d1733473e30ab0a3ba53d58141cc1d2509496ae672877
numpy@1.18.5
1.19
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
numpy@1.14.1
1.19
1
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
numpy@1:2.2.4+ds-1
no fix listed
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
numpy@1:1.17.4-5ubuntu3
numpy@1.17.4
1:1.17.4-5ubuntu3.1
1.19
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
numpy@1:1.17.4-5ubuntu3
numpy@1.17.4
1:1.17.4-5ubuntu3.1
1.19
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.