<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:23:12.671068+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-3490</id>
    <title>CVE-2026-3490 — picklescan - Universal Blocklist Bypass via pkgutil.resolve_name</title>
    <updated>2026-10-02T12:23:12.672822+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> picklescan</p>
<p>picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolving any dangerous function through indirect REDUCE calls. Remote attackers can invoke any blocked function such as os.system, builtins.exec, or subprocess.call to achieve remote code execution.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-3490"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vvpj-8cmc-gx39</id>
    <title>GHSA-vvpj-8cmc-gx39 — PickleScan's pkgutil.resolve_name has a universal blocklist bypass</title>
    <updated>2026-10-02T12:23:12.672874+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: picklescan</p>
<p>## Summary</p>
<p>`pkgutil.resolve_name()` is a Python stdlib function that resolves any `"module:attribute"` string to the corresponding Python object at runtime. By using `pkgutil.resolve_name` as the first REDUCE call in a pickle, an attacker can obtain a reference to ANY blocked function (e.g., `os.system`, `builtins.exec`, `subprocess.call`) without that function appearing in the pickle's opcodes. picklescan only sees `pkgutil.resolve_name` (which is not blocked) and misses the actual dangerous function entirely.</p>
<p>This defeats picklescan's **entire blocklist concept** — every single entry in `_unsafe_globals` can be bypassed.</p>
<p>## Severity</p>
<p>**Critical** (CVSS 10.0) — Universal bypass of all blocklist entries. Any blocked function can be invoked.</p>
<p>## Affected Versions</p>
<p>- picklescan &lt;= 1.0.3 (all versions including latest)</p>
<p>## Details</p>
<p>### How It Works</p>
<p>A pickle file uses two chained REDUCE calls:</p>
<p>```
1. STACK_GLOBAL: push pkgutil.resolve_name
2. REDUCE: call resolve_name("os:system") → returns os.system function object
3. REDUCE: call the returned function("malicious command") → RCE
```</p>
<p>picklescan's opcode scanner sees:
- `STACK_GLOBAL` with module=`pkgutil`, name=`resolve_name` → **NOT in blocklist** → CLEAN
- The second `REDUCE` operates on a stack value (the return of the first call), not on a global import → **invisible to scanner**</p>
<p>The string `"os:system"` is just data (a SHORT_BINUNICODE argument to the first REDUCE) — picklescan does not analyze REDUCE arguments, only…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vvpj-8cmc-gx39"/>
  </entry>
</feed>
