{"id":"CVE-2026-22607","aliases":["GHSA-p523-jq9w-64x9","PYSEC-2026-1371"],"url":"https://o3.security/vulnerability/CVE-2026-22607","summary":"Fickling Blocklist Bypass: cProfile.run()","details":"Fickling is a Python pickling decompiler and static analyzer. Fickling versions up to and including 0.1.6 do not treat Python's cProfile module as unsafe. Because of this, a malicious pickle that uses cProfile.run() is classified as SUSPICIOUS instead of OVERTLY_MALICIOUS. If a user relies on Fickling's output to decide whether a pickle is safe to deserialize, this misclassification can lead them to execute attacker-controlled code on their system. This affects any workflow or product that uses Fickling as a security gate for pickle deserialization. This issue has been patched in version 0.1.7.","published":"2026-01-10T01:35:04.920Z","modified":"2026-07-15T01:48:50.077175667Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"fickling","fixedVersion":"0.1.7"}],"fix":{"url":"https://github.com/trailofbits/fickling/commit/dc8ae12966edee27a78fe05c5745171a2b138d43","label":"trailofbits/fickling@dc8ae12"},"references":[{"type":"WEB","url":"https://github.com/trailofbits/fickling/releases/tag/v0.1.7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22607.json"},{"type":"ADVISORY","url":"https://github.com/trailofbits/fickling/security/advisories/GHSA-p523-jq9w-64x9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22607"},{"type":"FIX","url":"https://github.com/trailofbits/fickling/commit/dc8ae12966edee27a78fe05c5745171a2b138d43"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:50.077175667Z"}}