CVE-2025-71325
picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes, failing to track arguments in the correct range and allowing malicious pickle files to bypass detection. Attackers can craft pickle files with arguments at position zero to trigger unexpected exceptions and evade security scanning.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.47%
- CWE
- CWE-391
- Published
- 2026-06-17
- Last modified
- 2026-06-20
Affected products
- picklescan picklescan
- picklescan picklescan
Weakness type
Related vulnerabilities
- CVE-2026-74900 — openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode
- CVE-2024-52316 — Apache Tomcat: Authentication bypass when using Jakarta Authentication API
- CVE-2022-20849 — Cisco IOS XR Software Broadband Network Gateway PPPoE Denial of Service Vulnerability
- CVE-2024-23326 — Envoy incorrectly accepts HTTP 200 response for entering upgrade mode
- CVE-2023-32871 — In DA, there is a possible permission bypass due to an incorrect status check. This could lead to...
- CVE-2023-0572 — Unchecked Error Condition in froxlor/froxlor
- CVE-2022-22160 — Junos OS: MX Series: The bbe-smgd process crashes if an unsupported configuration exists and a PPPoE client sends a specific message
- CVE-2020-14383 — A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server...