216.73.217.22

CVE-2026-22608

· Published 10/01/2026 02:15 · Modified 10/01/2026 02:15

Labels: CVE-2026-22608 2026-01-10CVE-2026-22608CWE-184[email protected]

Essential information

Published
10/01/2026 02:15
Modified
10/01/2026 02:15
Author
Creator
CVSS
8.9 HIGH (v3) 8.9 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, both ctypes and pydoc modules aren't explicitly blocked. Even other existing pickle scanning tools (like picklescan) do not block pydoc.locate. Chaining these two together can achieve RCE while the scanner still reports the file as LIKELY_SAFE. This issue has been patched in version 0.1.7.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
fickling / fickling cpe:2.3:a:fickling:fickling:<0.1.7:*:*:*:*:*:*:*

References