CVE-2026-95897: Dask Loader core.py from_npy_stack deserialization
A security vulnerability has been detected in Dask up to 2026.8.0. This affects the function fromnpystack of the file dask/array/core.py of the component Loader. Such manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker needs network access, low-level privileges, and user interaction. The issue is described as remotely launchable, but exploitation requires a user to interact with attacker-controlled input.
Which Dask deployments are potentially affected?
Dask versions up to 2026.8.0 are identified as affected. The available information does not state whether any particular deployment configuration avoids the vulnerable from_npy_stack behavior.
Is public exploit activity a concern?
Yes. A public exploit has been disclosed and may be used, which increases the likelihood of attempted exploitation.
Is a fix available?
The supplied information does not identify a fixed version or vendor response. It states that the project was notified through an issue report but had not responded at the time of publication.