0.12.1
1 months ago
16 days ago
Known vulnerabilities in the tenso package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
tenso is a High-performance zero-copy tensor protocol Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling due to missing bounds checks during tensor deserialization. An attacker can exploit this by providing crafted serialized data that triggers excessive memory allocation or CPU consumption, leading to resource exhaustion and causing the application to become unresponsive or crash. How to fix Allocation of Resources Without Limits or Throttling? Upgrade | [,0.9.0) |