# CVE-2026-33155

## Summary

- **CVE ID:** CVE-2026-33155
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-400
- **Published:** Mar 20, 2026
- **Last Modified:** Mar 24, 2026

## Description

DeepDiff is a project focused on Deep Difference and search of any Python data. From version 5.0.0 to before version 8.6.2, the pickle unpickler _RestrictedUnpickler validates which classes can be loaded but does not limit their constructor arguments. A few of the types in SAFE_TO_IMPORT have constructors that allocate memory proportional to their input (builtins.bytes, builtins.list, builtins.range). A 40-byte pickle payload can force 10+ GB of memory, which crashes applications that load delta objects or call pickle_load with untrusted data. This issue has been patched in version 8.6.2.

## Affected Products

- seperman — deepdiff (>= 5.0.0, < 8.6.2)

## References

- [CNA](https://github.com/qlustered/deepdiff/security/advisories/GHSA-54jj-px8x-5w5q)
- [CNA](https://github.com/qlustered/deepdiff/commit/0d07ec21d12b46ef4e489383b363eadc22d990fb)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.45%
- **EPSS Percentile:** 38.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._