CVE-2025-10156
An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 picklescan allows a remote attacker to bypass security scans. This is achieved by crafting a ZIP archive containing a file with a bad Cyclic Redundancy Check (CRC), which causes the scanner to halt and fail to analyze the contents for malicious pickle files. When the file incorrectly considered safe is loaded, it can lead to the execution of malicious code.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 1.48%
- CWE
- CWE-755
- Published
- 2025-09-17
- Last modified
- 2026-03-12
Affected products
- mmaitre314 picklescan
Weakness type
Related vulnerabilities
- CVE-2026-49305 — Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation...
- CVE-2026-45819 — baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or...
- CVE-2026-52856 — Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
- CVE-2026-59952 — Valibot: record() issue paths can make flatten() throw for inherited Object property names
- CVE-2026-42792 — epmd permanent DoS via EMFILE on accept(2) in erts
- CVE-2026-48036 — Hulumi: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts
- CVE-2026-16730 — Dbus-broker: dbus-broker: session bus denial of service via emfile during peer setup
- CVE-2026-62994 — CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin