Headline
GHSA-94vc-p8w7-5p49: Bundled libwebp in imagecodecs vulnerable
imagecodecs versions before v2023.9.18 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-5129 (previously CVE-2023-4863). imagecodecs v2023.9.18 upgrades the bundled libwebp binary to v1.3.2.
Bundled libwebp in imagecodecs vulnerable
High severity GitHub Reviewed Published Oct 5, 2023 to the GitHub Advisory Database