{"id":"CVE-2020-28975","aliases":["GHSA-jxfp-4rvq-9h9m","PYSEC-2020-108"],"url":"https://o3.security/vulnerability/CVE-2020-28975","summary":"scikit-learn Denial of Service","details":"svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn 0.23.2 and other products, allows attackers to cause a denial of service (segmentation fault) via a crafted model SVM (introduced via pickle, json, or any other model permanence standard) with a large value in the _n_support array. NOTE: the scikit-learn vendor's position is that the behavior can only occur if the library's API is violated by an application that changes a private attribute.","published":"2020-11-21T21:15:10.680Z","modified":"2026-07-08T19:45:03.288400Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.035,"percentile":0.88285,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":3,"affectedPackages":[{"ecosystem":"PyPI","name":"scikit-learn","fixedVersion":"1.0.1"}],"fix":{"url":"https://github.com/scikit-learn/scikit-learn/commit/1bf13d567d3cd74854aa8343fd25b61dd768bb85","label":"scikit-learn/scikit-learn@1bf13d5"},"references":[{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2020/Nov/44"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202301-03"},{"type":"REPORT","url":"https://github.com/scikit-learn/scikit-learn/issues/18891"},{"type":"FIX","url":"https://github.com/scikit-learn/scikit-learn/commit/1bf13d567d3cd74854aa8343fd25b61dd768bb85"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/160281/SciKit-Learn-0.23.2-Denial-Of-Service.html"},{"type":"EVIDENCE","url":"https://github.com/cjlin1/libsvm/blob/9a3a9708926dec87d382c43b203f2ca19c2d56a0/svm.cpp#L2501"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T19:45:03.288400Z"}}