Skip to content

security: bound and validate NumPy headers - #5

Merged
Pyhroff merged 5 commits into
mainfrom
hardening/npy-header-bounds-20261011
Oct 11, 2026
Merged

Pyhroff merged 5 commits into
mainfrom
hardening/npy-header-bounds-20261011

Conversation

@Pyhroff

@Pyhroff Pyhroff commented Oct 11, 2026

Copy link
Copy Markdown
Owner

Summary

  • Bound NumPy .npy header parsing to 1 MiB before decoding or evaluating the header.
  • Validate magic/version/length fields, reject unsupported versions and truncated header bodies, and use UTF-8 for format v3.
  • Add regression tests for truncated and oversized headers plus a valid v3 header; include the test in the stdlib self-test runner.

Security rationale

ModelHawk parses untrusted serialized model artifacts. Header lengths are attacker-controlled; rejecting oversized or malformed headers limits parser work and ensures malformed input produces a conservative finding rather than being silently accepted. The scanner still never deserializes pickle payloads.

Validation

CI should run the complete existing self-test on the supported Python matrix. No security gate is disabled or relaxed.

@Pyhroff
Pyhroff merged commit 5331ced into main Oct 11, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant