{"id":"CVE-2026-22612","aliases":["GHSA-h4rm-mm56-xf63","PYSEC-2026-1370"],"url":"https://o3.security/vulnerability/CVE-2026-22612","summary":"Fickling vulnerable to detection bypass due to \"builtins\" blindness","details":"Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, Fickling is vulnerable to detection bypass due to \"builtins\" blindness. This issue has been patched in version 0.1.7.","published":"2026-01-10T01:35:25.197Z","modified":"2026-07-15T01:48:53.491597039Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"fickling","fixedVersion":"0.1.7"}],"fix":{"url":"https://github.com/trailofbits/fickling/commit/9f309ab834797f280cb5143a2f6f987579fa7cdf","label":"trailofbits/fickling@9f309ab"},"references":[{"type":"WEB","url":"https://github.com/trailofbits/fickling/releases/tag/v0.1.7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22612.json"},{"type":"ADVISORY","url":"https://github.com/trailofbits/fickling/security/advisories/GHSA-h4rm-mm56-xf63"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22612"},{"type":"FIX","url":"https://github.com/trailofbits/fickling/commit/9f309ab834797f280cb5143a2f6f987579fa7cdf"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:53.491597039Z"}}