Description
sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
Recommendation
Update the sqlite-vec package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.1.3
- Patched version(s): 0.1.3
References
Could your website be exposed too?
SmartScanner can check your website for Heap-based Buffer Overflow in sqlite-vec and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Buffer overflow in canvas - CVE-2020-8215
- bigint-buffer Vulnerable to Buffer Overflow via toBigIntLE() Function - CVE-2025-3194
- jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext - CVE-2024-28176
- Bootstrap Cross-Site Scripting (XSS) vulnerability for data-* attributes - CVE-2024-6485
You might also like:
See something that needs correcting? Let us knowUpdated October 02, 2024


