CVE-2026-56304
Last modified
CVE-2026-56304 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte files via logging.FileHandler class instantiation. Attackers can exploit this by crafting malicious pickle payloads to bypass RCE blocklists and create lock files or other filesystem artifacts, potentially causing denial of service or application disruption.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte files via logging.FileHandler class instantiation. Attackers can exploit this by crafting malicious pickle payloads to bypass RCE blocklists and create lock files or other filesystem artifacts, potentially causing denial of service or application disruption.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mmaitre314 | Picklescan | < 1.0.1 |
References
- https://github.com/mmaitre314/picklescan/security/advisories/GHSA-m7j5-r2p5-c39rExploit, Vendor Advisory
- https://github.com/mmaitre314/picklescan/security/advisories/GHSA-m7j5-r2p5-c39rExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-56304?
How severe is CVE-2026-56304?
How do I fix CVE-2026-56304?
Are you affected by CVE-2026-56304?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
