{"id":"CVE-2021-41500","aliases":["GHSA-8rh6-h94m-vj54","PYSEC-2021-870"],"url":"https://o3.security/vulnerability/CVE-2021-41500","summary":"Incorrect Comparison in cvxopt","details":"Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.","published":"2021-12-17T21:15:07.777Z","modified":"2026-07-08T06:03:36.322451687Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"cvxopt","fixedVersion":"1.2.7"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CXTPM3DGVYTYQ54OFCMXZVWVOMR7JM2D/"},{"type":"FIX","url":"https://github.com/cvxopt/cvxopt/issues/193"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T06:03:36.322451687Z"}}