tenso@0.7.0 vulnerabilities

High-performance zero-copy tensor protocol

  • latest version

    0.12.1

  • latest non vulnerable version

  • first published

    1 months ago

  • latest version published

    16 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the tenso package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Allocation of Resources Without Limits or Throttling

    tenso is a High-performance zero-copy tensor protocol

    Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling due to missing bounds checks during tensor deserialization. An attacker can exploit this by providing crafted serialized data that triggers excessive memory allocation or CPU consumption, leading to resource exhaustion and causing the application to become unresponsive or crash.

    How to fix Allocation of Resources Without Limits or Throttling?

    Upgrade tenso to version 0.9.0 or higher.

    [,0.9.0)