VYPR
High severity7.8NVD Advisory· Published Oct 26, 2021· Updated Jun 17, 2026

CVE-2021-41078

CVE-2021-41078

Description

Nameko through 2.13.0 can be tricked into performing arbitrary code execution when deserializing the config file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
namekoPyPI
< 2.14.02.14.0
namekoPyPI
>= 3.0.0rc0, < 3.0.0rc103.0.0rc10

Affected products

12
  • Nameko/Namekodescription
  • ghsa-coords
    Range: < 2.14.0
  • Nameko/Nameko10 versions
    cpe:2.3:a:nameko:nameko:*:*:*:*:*:*:*:*+ 9 more
    • cpe:2.3:a:nameko:nameko:*:*:*:*:*:*:*:*range: <=2.13.0
    • cpe:2.3:a:nameko:nameko:3.0.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:nameko:nameko:3.0.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:nameko:nameko:3.0.0:rc3:*:*:*:*:*:*
    • cpe:2.3:a:nameko:nameko:3.0.0:rc4:*:*:*:*:*:*
    • cpe:2.3:a:nameko:nameko:3.0.0:rc5:*:*:*:*:*:*
    • cpe:2.3:a:nameko:nameko:3.0.0:rc6:*:*:*:*:*:*
    • cpe:2.3:a:nameko:nameko:3.0.0:rc7:*:*:*:*:*:*
    • cpe:2.3:a:nameko:nameko:3.0.0:rc8:*:*:*:*:*:*
    • cpe:2.3:a:nameko:nameko:3.0.0:rc9:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.