OSPulse

Is numpy healthy, maintained, and safe?

55/ 100
numpyv2.5.1
Medium riskconfidence: Highview on pypi.org

No — numpy carries 1 unpatched critical advisory and should not be adopted without a remediation plan.

vital-signs traceirregular · weakening

The verdict

numpy earns a health score of 55/100, a medium risk rating, computed deterministically from live PyPI release history, and the OSV vulnerability database. No — numpy carries 1 unpatched critical advisory and should not be adopted without a remediation plan.

Its most recent release shipped on 4 July 2026 — 23 days ago — so development is clearly active. Across 134 releases the cadence has been steady, which is a good sign of an ongoing maintenance rhythm. PyPI doesn't expose a reliable maintainer count, so bus-factor isn't scored here — treat maintenance depth as unknown rather than assumed.

OSV lists 16 known advisories for numpy, including 1 critical and 4 high. Open critical advisories are the strongest possible signal to pin to a patched version, replace, or fork before shipping. Each advisory is listed with its OSV/GHSA identifier below.

numpy is usable but carries real signals — pin versions, watch for new advisories, and keep a fallback in mind. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own requirements.txt through the free health check, or have OSPulse monitor your whole dependency tree continuously.

Evidence trail — deterministic, auditable

Last release recency
23 days ago · active
Release cadence
steady · typical gap ~33d
Maintainer bus factor
not available from PyPI — not penalised
Known vulnerabilities (OSV)
16 advisories · 1 critical · 4 high
-45
Package age
19.7 years · 134 releases

Known vulnerabilities (16)

  • GHSA-2fc2-6r4j-p65hHIGHCVE-2014-1859PYSEC-2018-34

    Numpy arbitrary file write via symlink attack

  • GHSA-5545-2q6w-2gh6HIGHCVE-2021-41495PYSEC-2021-856

    NumPy NULL Pointer Dereference

  • GHSA-6p56-wp2h-9hxrMODERATECVE-2021-33430PYSEC-2021-854

    NumPy Buffer Overflow (Disputed)

  • GHSA-9fq2-x9r6-wfmfCRITICALCVE-2019-6446PYSEC-2019-108

    Numpy Deserialization of Untrusted Data

  • GHSA-cw6w-4rcx-xphcHIGHCVE-2014-1858PYSEC-2018-33

    Arbitrary file write in NumPy

  • GHSA-f7c7-j99h-c22fMODERATECVE-2021-41496PYSEC-2021-857

    Buffer Copy without Checking Size of Input in NumPy

  • GHSA-fpfv-jqm9-f5jmMODERATECVE-2021-34141PYSEC-2021-855

    Incorrect Comparison in NumPy

  • GHSA-frgw-fgh6-9g52HIGHCVE-2017-12852PYSEC-2017-1

    Numpy missing input validation

  • PYSEC-2017-1UNKNOWNCVE-2017-12852GHSA-frgw-fgh6-9g52

    The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.

  • PYSEC-2018-33UNKNOWNCVE-2014-1858GHSA-cw6w-4rcx-xphc

    __init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file.

  • PYSEC-2018-34UNKNOWNCVE-2014-1859GHSA-2fc2-6r4j-p65h

    (1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink att

  • PYSEC-2019-108UNKNOWNCVE-2019-6446GHSA-9fq2-x9r6-wfmf

    ** DISPUTED ** An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object

  • PYSEC-2021-854UNKNOWNCVE-2021-33430GHSA-6p56-wp2h-9hxr

    A Buffer Overflow vulnerability exists in NumPy 1.9.x in the PyArray_NewFromDescr_int function of ctors.c when specifying arrays of large dimensions (over 32) from Python code, which could let a malic

  • PYSEC-2021-855UNKNOWNCVE-2021-34141GHSA-fpfv-jqm9-f5jm

    Incomplete string comparison in the numpy.core component in NumPy1.9.x, which allows attackers to fail the APIs via constructing specific string objects.

  • PYSEC-2021-856UNKNOWNCVE-2021-41495GHSA-5545-2q6w-2gh6

    Null Pointer Dereference vulnerability exists in numpy.sort in NumPy &lt and 1.19 in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attacks

  • PYSEC-2021-857UNKNOWNCVE-2021-41496GHSA-f7c7-j99h-c22f

    Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative valu

Key facts

Latest version
v2.5.1
Last release
4 July 2026 (23 days ago)
Total releases
134
First release
2 December 2006
Package age
19.7 years
Maintainers
not exposed by PyPI
Known advisories
16
Confidence
High

Frequently asked

Is numpy still maintained?

Yes — numpy released as recently as 4 July 2026 (23 days ago), so it is actively maintained.

Does numpy have known security vulnerabilities?

Yes — OSV lists 16 advisories for numpy, including 1 rated critical. See the advisory list on this page for the OSV/GHSA identifiers.

Is numpy safe to use?

No — numpy carries 1 unpatched critical advisory and should not be adopted without a remediation plan. OSPulse rates it 55/100 (medium risk) based on release recency, cadence and known vulnerabilities.

Other PyPI packages we've checked

Browse all checked packages →

numpy is one package. What about the other hundreds in your tree?

Paste your own requirements.txt into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.

Data from the PyPI registry & OSV.dev · snapshot generated 2026-07-27 · scores are deterministic and recomputed on each refresh.