{"id":"CVE-2021-41499","aliases":["GHSA-5f5c-687x-g5qm","PYSEC-2026-743"],"title":"Classic Buffer Overflow in pyo","summary":"Classic Buffer Overflow in pyo","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","vendor":"pyo","product":"pyo","ecosystem":"pip","affected":["pyo < 1.0.3"],"patched":["pyo 1.0.3"],"published":"2022-01-07","updated":"2026-07-06","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-5f5c-687x-g5qm","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-41499"},{"url":"https://github.com/belangeo/pyo/issues/222"},{"url":"https://github.com/belangeo/pyo"}],"tags":["osv","pip"],"epss":0.01401,"epssPercentile":0.7132,"ingestedAt":"2026-07-08T18:25:45.986Z","slug":"CVE-2021-41499","body":"## Overview\n\nBuffer Overflow Vulnerability exists in ajaxsoundstudio.com in Pyo < 1.03 in the Server_debug function, which allows remote attackers to conduct DoS attacks by deliberately passing on an overlong audio file name.\n\n## Affected packages\n\n- `pyo < 1.0.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `pyo 1.0.3`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}