Skip to content

[ML] Bump sentencepiece and zipp to patched versions for Snyk findings - #3229

Open
edsavage wants to merge 1 commit into
elastic:mainfrom
edsavage:fix/snyk-python-dep-bumps
Open

edsavage wants to merge 1 commit into
elastic:mainfrom
edsavage:fix/snyk-python-dep-bumps

Conversation

@edsavage

@edsavage edsavage commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Summary

Resolves two Snyk vulnerability findings in dev/CI-only Python tooling (not shipped in the product):

  • sentencepiece (dev-tools/extract_model_ops/requirements.txt): floor-pin >=0.2.0 → >=0.2.1 to pull in the fix for CVE-2026-1260 (SNYK-PYTHON-SENTENCEPIECE-15091567) — a heap-based buffer overflow when parsing a malicious precompiled normalization model.
  • zipp (dev-tools/test-requirements.txt): add an explicit floor pin >=3.19.1 for CVE-2024-5569 (SNYK-PYTHON-ZIPP-7430899) — an infinite-loop DoS on malformed zip paths. zipp is a transitive dependency of the dev-tools/unittest pytest suite (via importlib.metadata), so a direct floor pin is used to guarantee the patched version.

Both findings surfaced in the Snyk Open Source reports for elastic/ml-cpp. These are the only two Snyk Open Source findings for this repo; the remaining ~925 findings are Snyk Container findings against the base OS packages of the dev/build Docker images, which are handled separately via base-image refreshes.

Test plan

  • Fresh venv + pip install -r dev-tools/test-requirements.txt resolves zipp to a patched version (4.1.0 ≥ 3.19.1).
  • dev-tools/unittest pytest suite passes (95 passed, 3 skipped — the torch/transformers-gated extract_model_ops config tests): mirrors CI's .buildkite/scripts/steps/dev_tools_pytest.sh.
  • sentencepiece pin installs and imports cleanly (resolves to ≥ 0.2.1). Note: no offline test exercises sentencepiece directly (it is a lazy runtime dep of transformers tokenizers that requires a model download), so this is an install/import sanity check.

Made with Cursor

Address two Snyk vulnerability findings in dev/CI-only Python tooling:

- sentencepiece: floor-pin to >=0.2.1 to pull in the fix for CVE-2026-1260
  (SNYK-PYTHON-SENTENCEPIECE-15091567), a heap overflow when parsing a
  malicious precompiled normalization model.
- zipp: add an explicit floor pin >=3.19.1 (it is a transitive dep of the
  dev-tools pytest suite) for CVE-2024-5569 (SNYK-PYTHON-ZIPP-7430899), an
  infinite-loop DoS on malformed zip paths.

Co-authored-by: Cursor <cursoragent@cursor.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants