CVE-2026-22607 impacts Fickling versions up to 0.1.6, a Python pickling decompiler and static analyzer. The vulnerability stems from Fickling's failure to correctly identify malicious pickles utilizing the cProfile module, classifying them as "SUSPICIOUS" instead of "OVERTLY_MALICIOUS." This misclassification can lead users to inadvertently deserialize attacker-controlled code, resulting in high impact to confidentiality, integrity, and availability (CVSS 7.8 HIGH). While the vulnerability has been patched in version 0.1.7, there is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.7CPE matchmatch criteria | cpe:2.3:a:trailofbits:fickling:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.