<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 12:08:23 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-03615</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-03615</link>
      <description>bdu:2026-03615</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-03615</guid>
    </item>
    <item>
      <title>BREW-bzt-CVE-2025-61765 — python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain…</title>
      <link>https://cve.radiocsirt.org/vuln/brew-bzt-cve-2025-61765</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: bzt&lt;/p&gt;
&lt;p&gt;### Summary
A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications.&lt;/p&gt;
&lt;p&gt;### Details
When Socket.IO servers are configured to use a message queue backend such as Redis for inter-server communication, messages sent between the servers are encoded using the `pickle` Python module. When a server receives one of these messages through the message queue, it assumes it is trusted and immediately deserializes it.&lt;/p&gt;
&lt;p&gt;The vulnerability stems from deserialization of messages using Python&amp;#39;s `pickle.loads()` function. Having previously obtained access to the message queue, the attacker can send a python-socketio server a crafted pickle payload that executes arbitrary code during deserialization via Python&amp;#39;s `__reduce__` method.&lt;/p&gt;
&lt;p&gt;### Impact
This vulnerability only affects deployments with a compromised message queue. The attack can lead to the attacker executing random code in the context of, and with the privileges of a Socket.IO server process.&lt;/p&gt;
&lt;p&gt;Single-server systems that do not use a message queue, and multi-server systems with a secure message queue are not vulnerable.&lt;/p&gt;
&lt;p&gt;### Remediation
In addition to making sure standard security practices are followed in the deployment of the message queue, users of the python-socketio package ca…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: bzt&lt;/p&gt;
&lt;p&gt;### Summary
A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications.&lt;/p&gt;
&lt;p&gt;### Details
When Socket.IO servers are configured to use a message queue backend such as Redis for inter-server communication, messages sent between the servers are encoded using the `pickle` Python module. When a server receives one of these messages through the message queue, it assumes it is trusted and immediately deserializes it.&lt;/p&gt;
&lt;p&gt;The vulnerability stems from deserialization of messages using Python&amp;#39;s `pickle.loads()` function. Having previously obtained access to the message queue, the attacker can send a python-socketio server a crafted pickle payload that executes arbitrary code during deserialization via Python&amp;#39;s `__reduce__` method.&lt;/p&gt;
&lt;p&gt;### Impact
This vulnerability only affects deployments with a compromised message queue. The attack can lead to the attacker executing random code in the context of, and with the privileges of a Socket.IO server process.&lt;/p&gt;
&lt;p&gt;Single-server systems that do not use a message queue, and multi-server systems with a secure message queue are not vulnerable.&lt;/p&gt;
&lt;p&gt;### Remediation
In addition to making sure standard security practices are followed in the deployment of the message queue, users of the python-socketio package ca…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-bzt-cve-2025-61765</guid>
    </item>
    <item>
      <title>EUVD-2026-256628</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-256628</link>
      <description>EUVD-2026-256628</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-256628</guid>
    </item>
    <item>
      <title>fkie_cve-2025-61765</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-61765</link>
      <description>&lt;p&gt;python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications. When Socket.IO servers are configured to use a message queue backend such as Redis for inter-server communication, messages sent between the servers are encoded using the `pickle` Python module. When a server receives one of these messages through the message queue, it assumes it is trusted and immediately deserializes it. The vulnerability stems from deserialization of messages using Python&amp;#39;s `pickle.loads()` function. Having previously obtained access to the message queue, the attacker can send a python-socketio server a crafted pickle payload that executes arbitrary code during deserialization via Python&amp;#39;s `__reduce__` method. This vulnerability only affects deployments with a compromised message queue. The attack can lead to the attacker executing random code in the context of, and with the privileges of a Socket.IO server process. Single-server systems that do not use a message queue, and multi-server systems with a secure message queue are not vulnerable. In addition to making sure standard security practices are followed in the deployment of the message queue, users of…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications. When Socket.IO servers are configured to use a message queue backend such as Redis for inter-server communication, messages sent between the servers are encoded using the `pickle` Python module. When a server receives one of these messages through the message queue, it assumes it is trusted and immediately deserializes it. The vulnerability stems from deserialization of messages using Python&amp;#39;s `pickle.loads()` function. Having previously obtained access to the message queue, the attacker can send a python-socketio server a crafted pickle payload that executes arbitrary code during deserialization via Python&amp;#39;s `__reduce__` method. This vulnerability only affects deployments with a compromised message queue. The attack can lead to the attacker executing random code in the context of, and with the privileges of a Socket.IO server process. Single-server systems that do not use a message queue, and multi-server systems with a secure message queue are not vulnerable. In addition to making sure standard security practices are followed in the deployment of the message queue, users of…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-61765</guid>
    </item>
    <item>
      <title>GHSA-g8c6-8fjj-2r4m — python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g8c6-8fjj-2r4m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: python-socketio&lt;/p&gt;
&lt;p&gt;### Summary
A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications.&lt;/p&gt;
&lt;p&gt;### Details
When Socket.IO servers are configured to use a message queue backend such as Redis for inter-server communication, messages sent between the servers are encoded using the `pickle` Python module. When a server receives one of these messages through the message queue, it assumes it is trusted and immediately deserializes it.&lt;/p&gt;
&lt;p&gt;The vulnerability stems from deserialization of messages using Python&amp;#39;s `pickle.loads()` function. Having previously obtained access to the message queue, the attacker can send a python-socketio server a crafted pickle payload that executes arbitrary code during deserialization via Python&amp;#39;s `__reduce__` method.&lt;/p&gt;
&lt;p&gt;### Impact
This vulnerability only affects deployments with a compromised message queue. The attack can lead to the attacker executing random code in the context of, and with the privileges of a Socket.IO server process.&lt;/p&gt;
&lt;p&gt;Single-server systems that do not use a message queue, and multi-server systems with a secure message queue are not vulnerable.&lt;/p&gt;
&lt;p&gt;### Remediation
In addition to making sure standard security practices are followed in the deployment of the message queue, users of the python-socketio package ca…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: python-socketio&lt;/p&gt;
&lt;p&gt;### Summary
A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications.&lt;/p&gt;
&lt;p&gt;### Details
When Socket.IO servers are configured to use a message queue backend such as Redis for inter-server communication, messages sent between the servers are encoded using the `pickle` Python module. When a server receives one of these messages through the message queue, it assumes it is trusted and immediately deserializes it.&lt;/p&gt;
&lt;p&gt;The vulnerability stems from deserialization of messages using Python&amp;#39;s `pickle.loads()` function. Having previously obtained access to the message queue, the attacker can send a python-socketio server a crafted pickle payload that executes arbitrary code during deserialization via Python&amp;#39;s `__reduce__` method.&lt;/p&gt;
&lt;p&gt;### Impact
This vulnerability only affects deployments with a compromised message queue. The attack can lead to the attacker executing random code in the context of, and with the privileges of a Socket.IO server process.&lt;/p&gt;
&lt;p&gt;Single-server systems that do not use a message queue, and multi-server systems with a secure message queue are not vulnerable.&lt;/p&gt;
&lt;p&gt;### Remediation
In addition to making sure standard security practices are followed in the deployment of the message queue, users of the python-socketio package ca…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g8c6-8fjj-2r4m</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15613-1 — python311-python-socketio-5.14.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15613-1</link>
      <description>&lt;p&gt;python311-python-socketio-5.14.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-python-socketio-5.14.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15613-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-1854 — python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain…</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1854</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: python-socketio&lt;/p&gt;
&lt;p&gt;### Summary
A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications.&lt;/p&gt;
&lt;p&gt;### Details
When Socket.IO servers are configured to use a message queue backend such as Redis for inter-server communication, messages sent between the servers are encoded using the `pickle` Python module. When a server receives one of these messages through the message queue, it assumes it is trusted and immediately deserializes it.&lt;/p&gt;
&lt;p&gt;The vulnerability stems from deserialization of messages using Python&amp;#39;s `pickle.loads()` function. Having previously obtained access to the message queue, the attacker can send a python-socketio server a crafted pickle payload that executes arbitrary code during deserialization via Python&amp;#39;s `__reduce__` method.&lt;/p&gt;
&lt;p&gt;### Impact
This vulnerability only affects deployments with a compromised message queue. The attack can lead to the attacker executing random code in the context of, and with the privileges of a Socket.IO server process.&lt;/p&gt;
&lt;p&gt;Single-server systems that do not use a message queue, and multi-server systems with a secure message queue are not vulnerable.&lt;/p&gt;
&lt;p&gt;### Remediation
In addition to making sure standard security practices are followed in the deployment of the message queue, users of the python-socketio package ca…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: python-socketio&lt;/p&gt;
&lt;p&gt;### Summary
A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications.&lt;/p&gt;
&lt;p&gt;### Details
When Socket.IO servers are configured to use a message queue backend such as Redis for inter-server communication, messages sent between the servers are encoded using the `pickle` Python module. When a server receives one of these messages through the message queue, it assumes it is trusted and immediately deserializes it.&lt;/p&gt;
&lt;p&gt;The vulnerability stems from deserialization of messages using Python&amp;#39;s `pickle.loads()` function. Having previously obtained access to the message queue, the attacker can send a python-socketio server a crafted pickle payload that executes arbitrary code during deserialization via Python&amp;#39;s `__reduce__` method.&lt;/p&gt;
&lt;p&gt;### Impact
This vulnerability only affects deployments with a compromised message queue. The attack can lead to the attacker executing random code in the context of, and with the privileges of a Socket.IO server process.&lt;/p&gt;
&lt;p&gt;Single-server systems that do not use a message queue, and multi-server systems with a secure message queue are not vulnerable.&lt;/p&gt;
&lt;p&gt;### Remediation
In addition to making sure standard security practices are followed in the deployment of the message queue, users of the python-socketio package ca…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1854</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-61765</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-61765</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: python-socketio, Ubuntu:22.04:LTS: python-socketio, Ubuntu:24.04:LTS: python-socketio, Ubuntu:25.10: python-socketio, Ubuntu:26.04:LTS: python-socketio&lt;/p&gt;
&lt;p&gt;python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications. When Socket.IO servers are configured to use a message queue backend such as Redis for inter-server communication, messages sent between the servers are encoded using the `pickle` Python module. When a server receives one of these messages through the message queue, it assumes it is trusted and immediately deserializes it. The vulnerability stems from deserialization of messages using Python&amp;#39;s `pickle.loads()` function. Having previously obtained access to the message queue, the attacker can send a python-socketio server a crafted pickle payload that executes arbitrary code during deserialization via Python&amp;#39;s `__reduce__` method. This vulnerability only affects deployments with a compromised message queue. The attack can lead to the attacker executing random code in the context of, and with the privileges of a Socket.IO server process. Single-server systems that do not use a message queue, and multi-server systems with a secure message queue are not vulnerable. In addition to making sure standard security practices are followed in the deployment of the message queue, users of…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: python-socketio, Ubuntu:22.04:LTS: python-socketio, Ubuntu:24.04:LTS: python-socketio, Ubuntu:25.10: python-socketio, Ubuntu:26.04:LTS: python-socketio&lt;/p&gt;
&lt;p&gt;python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications. When Socket.IO servers are configured to use a message queue backend such as Redis for inter-server communication, messages sent between the servers are encoded using the `pickle` Python module. When a server receives one of these messages through the message queue, it assumes it is trusted and immediately deserializes it. The vulnerability stems from deserialization of messages using Python&amp;#39;s `pickle.loads()` function. Having previously obtained access to the message queue, the attacker can send a python-socketio server a crafted pickle payload that executes arbitrary code during deserialization via Python&amp;#39;s `__reduce__` method. This vulnerability only affects deployments with a compromised message queue. The attack can lead to the attacker executing random code in the context of, and with the privileges of a Socket.IO server process. Single-server systems that do not use a message queue, and multi-server systems with a secure message queue are not vulnerable. In addition to making sure standard security practices are followed in the deployment of the message queue, users of…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-61765</guid>
    </item>
  </channel>
</rss>
