CVE-2026-95897

Source
https://cve.org/CVERecord?id=CVE-2026-95897
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-95897.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-95897
Downstream
Published
2026-09-23T00:30:14Z
Modified
2026-09-24T03:47:53Z
Severity
  • 2.0 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Dask Loader core.py from_npy_stack deserialization
Details

A security vulnerability has been detected in Dask up to 2026.8.0. This affects the function from_npy_stack of the file dask/array/core.py of the component Loader. Such manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-20",
        "CWE-502"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/95xxx/CVE-2026-95897.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "2026.0"
                },
                {
                    "last_affected":  "2026.0"
                },
                {
                    "introduced":  "2026.2"
                },
                {
                    "last_affected":  "2026.2"
                },
                {
                    "introduced":  "2026.4"
                },
                {
                    "last_affected":  "2026.4"
                },
                {
                    "introduced":  "2026.5"
                },
                {
                    "last_affected":  "2026.5"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/dask/dask

Affected ranges

Type
GIT
Repo
https://github.com/dask/dask
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "2026.1"
        },
        {
            "last_affected":  "2026.1"
        },
        {
            "introduced":  "2026.3"
        },
        {
            "last_affected":  "2026.3"
        },
        {
            "introduced":  "2026.6"
        },
        {
            "last_affected":  "2026.6"
        },
        {
            "introduced":  "2026.7"
        },
        {
            "last_affected":  "2026.7"
        },
        {
            "introduced":  "2026.8.0"
        },
        {
            "last_affected":  "2026.8.0"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

2026.*
2026.1
2026.1.0
2026.1.1
2026.1.2
2026.3
2026.3.0
2026.6
2026.6.0
2026.7
2026.7.0
2026.8.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-95897.json"