Is numpy healthy, maintained, and safe?
No — numpy carries 1 unpatched critical advisory and should not be adopted without a remediation plan.
The verdict
numpy earns a health score of 55/100, a medium risk rating, computed deterministically from live PyPI release history, and the OSV vulnerability database. No — numpy carries 1 unpatched critical advisory and should not be adopted without a remediation plan.
Its most recent release shipped on 4 July 2026 — 23 days ago — so development is clearly active. Across 134 releases the cadence has been steady, which is a good sign of an ongoing maintenance rhythm. PyPI doesn't expose a reliable maintainer count, so bus-factor isn't scored here — treat maintenance depth as unknown rather than assumed.
OSV lists 16 known advisories for numpy, including 1 critical and 4 high. Open critical advisories are the strongest possible signal to pin to a patched version, replace, or fork before shipping. Each advisory is listed with its OSV/GHSA identifier below.
numpy is usable but carries real signals — pin versions, watch for new advisories, and keep a fallback in mind. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own requirements.txt through the free health check, or have OSPulse monitor your whole dependency tree continuously.
Evidence trail — deterministic, auditable
Known vulnerabilities (16)
Numpy arbitrary file write via symlink attack
NumPy NULL Pointer Dereference
NumPy Buffer Overflow (Disputed)
Numpy Deserialization of Untrusted Data
Arbitrary file write in NumPy
Buffer Copy without Checking Size of Input in NumPy
Incorrect Comparison in NumPy
Numpy missing input validation
The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.
__init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file.
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink att
** DISPUTED ** An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object
A Buffer Overflow vulnerability exists in NumPy 1.9.x in the PyArray_NewFromDescr_int function of ctors.c when specifying arrays of large dimensions (over 32) from Python code, which could let a malic
Incomplete string comparison in the numpy.core component in NumPy1.9.x, which allows attackers to fail the APIs via constructing specific string objects.
Null Pointer Dereference vulnerability exists in numpy.sort in NumPy < and 1.19 in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attacks
Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative valu
Key facts
- Latest version
- v2.5.1
- Last release
- 4 July 2026 (23 days ago)
- Total releases
- 134
- First release
- 2 December 2006
- Package age
- 19.7 years
- Maintainers
- not exposed by PyPI
- Known advisories
- 16
- Confidence
- High
Frequently asked
Is numpy still maintained?
Yes — numpy released as recently as 4 July 2026 (23 days ago), so it is actively maintained.
Does numpy have known security vulnerabilities?
Yes — OSV lists 16 advisories for numpy, including 1 rated critical. See the advisory list on this page for the OSV/GHSA identifiers.
Is numpy safe to use?
No — numpy carries 1 unpatched critical advisory and should not be adopted without a remediation plan. OSPulse rates it 55/100 (medium risk) based on release recency, cadence and known vulnerabilities.
Other PyPI packages we've checked
numpy is one package. What about the other hundreds in your tree?
Paste your own requirements.txt into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.
Data from the PyPI registry & OSV.dev · snapshot generated 2026-07-27 · scores are deterministic and recomputed on each refresh.
