Safety vulnerability ID: 73020
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Inference has upgraded its OpenCV dependency from opencv_python==4.7.0.72 to opencv-python>=4.8.1.78,<=4.10.0.84 to address a security vulnerability (CVE-2023-4863) found in the bundled libwebp binaries.
Latest version: 0.29.1
With no prior knowledge of machine learning or device-specific deployment, you can deploy a computer vision model to a range of devices and environments using Roboflow Inference.
❗IMPORTANT ❗Security issue in `opencv-python`
This PR provides fix for the following security issue:
opencv-python versions before v4.8.1.78 bundled libwebp binaries in wheels that are vulnerable to https://github.com/advisories/GHSA-j7hp-h8jx-5ppr. opencv-python v4.8.1.78 upgrades the bundled libwebp binary to v1.3.2.
We advise all clients using `inference` to migrate, especially in production environments.
**Full Changelog**: https://github.com/roboflow/inference/compare/v0.17.0...v0.17.1
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application