- Package:
- src:fsspec
- Source:
- src:fsspec
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-10-05 21:51:03 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for fsspec. CVE-2026-104851[0]: | fsspec is a specification and Python implementation framework for | filesystem interfaces. From 0.9.0 until 2026.6.0, | fsspec.implementations.reference.ReferenceFileSystem evaluates | fields from Kerchunk reference JSON documents through unrestricted | jinja2.Template(...).render(...) calls in | _process_references1._render_jinja, _process_templates, and | _process_gen in fsspec/implementations/reference.py. A document | supplied inline or fetched from an attacker-controlled URL can | provide template expressions that execute Python code when the | reference filesystem is opened, including through consumers such as | xarray, before referenced data is read. The _process_gen path is | reached whenever a document includes a gen array, while the other | paths depend on template-related options and values. This issue is | fixed in version 2026.6.0. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-104851 https://www.cve.org/CVERecord?id=CVE-2026-104851 [1] https://github.com/fsspec/filesystem_spec/security/advisories/GHSA-27vj-qcqg-25rc [2] https://github.com/fsspec/filesystem_spec/commit/86438783f93b1398ef245b92f0e6063b445b611c [3] https://github.com/fsspec/filesystem_spec/commit/a1c16ab3f07f354aa371c38f7b1b07ea7fd4c5c8 Rgards, Salvatore
We believe that the bug you reported is fixed in the latest version of
fsspec, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1149800@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Colin Watson <cjwatson@debian.org> (supplier of updated fsspec package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 05 Oct 2026 22:32:27 +0100
Source: fsspec
Architecture: source
Version: 2026.9.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Colin Watson <cjwatson@debian.org>
Closes: 1149800
Changes:
fsspec (2026.9.0-1) unstable; urgency=medium
.
* Team upload.
* New upstream release:
- CVE-2026-104851: Fix remote code execution by server-side template
injection in ReferenceFileSystem (closes: #1149800).
Checksums-Sha1:
f022f09c52eaa14ba90097353d89d57c856e27de 2823 fsspec_2026.9.0-1.dsc
862f45892b204cb068da059e6e2432d7d67a6a9a 501779 fsspec_2026.9.0.orig.tar.gz
08583f8090c789d503de78f67692d4133ae96dee 7952 fsspec_2026.9.0-1.debian.tar.xz
97de0554b76fcef61603eaa9c48f097cd75c2105 890348 fsspec_2026.9.0-1.git.tar.xz
001eb4955a2a0f659615b4c832afaf977cf8da49 17732 fsspec_2026.9.0-1_source.buildinfo
Checksums-Sha256:
a3950ade6975313223b1f8b600c104afd4e6f4b118f8d6aa18ca1d0bf3030e53 2823 fsspec_2026.9.0-1.dsc
3abdf1d579006d4b176c7ff1d5d37d579dd0dd78b80b9e18d3cc1d1185b93fe8 501779 fsspec_2026.9.0.orig.tar.gz
c5511a40057599ec1ffbee60d292dba7ee8d4d97e3d86dc38babd072af12455c 7952 fsspec_2026.9.0-1.debian.tar.xz
dcd8304ee96738f6d6bba0029e3a91b725e27e9c40f890008da1f3bea919549a 890348 fsspec_2026.9.0-1.git.tar.xz
1258a001bc9150e9cbaf6e7905a71e20ab6f369527e4270849ad92daedbb1d75 17732 fsspec_2026.9.0-1_source.buildinfo
Files:
97d8ff0e5424a89d66a02d55b3e95e38 2823 python optional fsspec_2026.9.0-1.dsc
921d537603a86f047da97d7928de5597 501779 python optional fsspec_2026.9.0.orig.tar.gz
4ccd4f10f5ae72863cf9bb418aa1f80c 7952 python optional fsspec_2026.9.0-1.debian.tar.xz
918882783a832e0f368b8741828b5af3 890348 python optional fsspec_2026.9.0-1.git.tar.xz
c5d247ec95a6334a66bc9f4f461e421c 17732 python optional fsspec_2026.9.0-1_source.buildinfo
Git-Tag-Info: tag=f7da3addf7664b6b2364de6eb9dace8d04c5a94d fp=ac0a4ff12611b6fccf01c111393587d97d86500b
Git-Tag-Tagger: Colin Watson <cjwatson@debian.org>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmrEGM4ACgkQYG0ITkaD
wHlt/hAAiTCvg3px2rATxbMnTRqH3FiOvUNyIehmBP4H7859S4W6I1FFQxR3GoNI
pie8Kvv85NmLivXmDBBWMBmmQp9L7Wt6xe28dYForxCruznTM+5x2hfIpWFljW75
kJwxAYSW2/IeO6u4fcSPJ71z0ujh1y0VklOn6hUTEdU4Gy7Q3x/ciO/sPlH+iSc6
u1Uf/0u2PePaNa4CapnlnHOhBGKQu41VO5PI1a42IDReVa09Bj9RGHnEhiOM/5Hp
h6r0BgwByfJRatbRir1Qkwi0sk17G5bWCZo5NwHx1f5b/o9cSs5++QVGyt9QjhRt
2U463Sr+Ee2FkfgVr1py4SZLp37R5AxtLgvKc8XUTGYxG2nKtctB2UWeYLAJJ2oj
o4cOLDx/Jc0zDI5OA2zOCFsc73E9D5WPIejXDJ5Srg8ubRw/PllsmraqPTSqsbBI
m7nUEy2BIZQN8jsNZtcqodfm6YzjbSEZXibpOsLF63fnxK4xr/6tAsq4eYe5+B7F
nAIkihHcg3GkNQ/TG45twyPtBH3wp/sA7aJG0ON1ftDrTgy8Mst5C1sFypSAp6GL
SJVvl2QDupwFBUt0q3nPn0Ji2SLG5MVPKc1ctMiA5Dgz+KOAwbNoVO2UoyaK6qhq
4pJ+Ji7CG8IadgUjTUA/jzeA7rlwKSh3pLgjvuXEnJFqwAmuzos=
=i4/0
-----END PGP SIGNATURE-----