Skip to content

Conversation

@progval
Copy link
Contributor

@progval progval commented Jan 16, 2026

eg. for PYSEC-2023-72, version 3.2.0 is said to both fix and introduce the vulnerability.

My guess is this inconsistency comes from https://nvd.nist.gov/vuln/detail/cve-2023-32007 claiming 'up to version 3.1.3' even though this is the last version before version 3.2.0, which is also vulnerable

…roduce and fix it

My guess is this inconsistency comes from https://nvd.nist.gov/vuln/detail/cve-2023-32007 claiming
'up to version 3.1.3' even though this is the last version before version 3.2.0, which is also vulnerable
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant