GHSA-vxp9-wv2f-wqmw critical
Deserialization of Untrusted Data in superset
Affected range
ECOSYSTEM: introduced 0; fixed 0.23ECOSYSTEM: introduced 0; fixed 0.23.0Fixed versions: 0.23, 0.23.0
Superset has moved to apache-superset, as of 0.34.0 onwards, please pip install apache-superset
Evidence path
RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.
Latest version
0.30.1
Published advisories match this version
Known exploitation
No KEV match
Checked by exact CVE identifier
Highest advisory severity
Critical
2 active advisories
The registry confirms the version, then OSV checks advisories for that exact value.
Published records
Affected range
ECOSYSTEM: introduced 0; fixed 0.23ECOSYSTEM: introduced 0; fixed 0.23.0Fixed versions: 0.23, 0.23.0
Affected range
ECOSYSTEM: introduced 0; last affected 0.34.0