CVE-2026-33155 identifies a denial-of-service vulnerability in the DeepDiff Python library, affecting versions 5.0.0 through 8.6.1. The flaw allows an attacker to craft a small (40-byte) pickle payload that, when processed by DeepDiff's _RestrictedUnpickler, forces applications to allocate over 10 GB of memory, leading to a crash. This high-severity vulnerability (CVSS 8.7) has a network attack vector and low attack complexity, primarily impacting system availability through uncontrolled resource consumption (CWE-400). While there is no evidence of active exploitation or public exploit code, the issue has been patched in DeepDiff version 8.6.2, and a SUSE security update has been released.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.0, < 8.6.2CPE matchmatch criteria | cpe:2.3:a:qluster:deepdiff:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.