{"id":"CVE-2025-46417","aliases":["GHSA-93mv-x874-956g","PYSEC-2025-34"],"url":"https://o3.security/vulnerability/CVE-2025-46417","summary":"Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate","details":"The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deserialization.","published":"2025-04-24T00:00:00Z","modified":"2026-08-08T03:48:13.997350854Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"picklescan","fixedVersion":"0.0.25"}],"fix":{"url":"https://github.com/mmaitre314/picklescan/pull/40","label":"mmaitre314/picklescan#40"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/46xxx/CVE-2025-46417.json"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-93mv-x874-956g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-46417"},{"type":"FIX","url":"https://github.com/mmaitre314/picklescan/pull/40"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:13.997350854Z"}}