---
id: CVE-2021-34141
title: >-
  An incomplete string comparison in the numpy.core component in NumPy before
  1.22.0 allows attackers to trigger slightly incorrect copying by constructing
  specific string objects
summary: >-
  An incomplete string comparison in the numpy.core component in NumPy before
  1.22.0 allows attackers to trigger slightly incorrect copying by constructing
  specific string objects. NOTE: the vendor states that this reported code
  behavior i…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-697
vendor: numpy
product: numpy
affected:
  - numpy < 1.22.0
  - communications_cloud_native_core_policy = 22.1.3
patched:
  - numpy 1.22.0
published: '2021-12-17'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:35.733'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-34141'
references:
  - url: 'https://github.com/numpy/numpy/issues/18993'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: cve@mitre.org
  - url: 'https://github.com/numpy/numpy/issues/18993'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01561
epssPercentile: 0.74478
ingestedAt: '2026-10-08T22:11:53.743Z'
---

## Overview

An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."

## Affected

- `numpy < 1.22.0`
- `communications_cloud_native_core_policy = 22.1.3`

## Remediation

Upgrade past the affected range:

- `numpy 1.22.0`
