Trail of Bits is a security research and tools vendor whose vulnerability footprint concentrates in open-source libraries for deserialization, code signing, and cryptographic validation—tools widely adopted by security practitioners and embedded in downstream applications. Its disclosures reflect the complex trust boundaries characteristic of parsing and validation tooling: deserialization weaknesses, incomplete input filtering, signature verification flaws, and certificate validation gaps recur across products such as Fickling, Uthenticode, and the RFC 3161 client. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trailofbits over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-14535CRITICAL In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it in | Jul 4, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-14534HIGH Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS denylist (fic | Jul 4, 2026 | 8.8 | 40 | NO | NO |
CVE-2026-33753HIGH rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an Authorization Bypass vulnerability in rfc3161-client's signa | Apr 8, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-22612HIGH Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, Fickling is vulnerable to detection bypass due to "builtins" blindness. This issue has been pa | Jan 10, 2026 | 7.8 | 26 | NO | NO |
CVE-2026-22607HIGH Fickling is a Python pickling decompiler and static analyzer. Fickling versions up to and including 0.1.6 do not treat Python's cProfile module as unsafe. Because of this, a malici | Jan 10, 2026 | 7.8 | 26 | NO | NO |
CVE-2025-67748HIGH Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of unsafe module imports. This led to | Dec 16, 2025 | 7.8 | 26 | NO | NO |
CVE-2025-67747HIGH Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 are missing `marshal` and `types` from the block list of unsafe module imports. Fickling start | Dec 16, 2025 | 7.8 | 26 | NO | NO |
CVE-2023-39969CRITICAL uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Version 1.0.9 of uthenticode hashed the entire file rather than hashing secti | Aug 9, 2023 | 9.8 | 26 | NO | NO |
CVE-2026-22609HIGH Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, the unsafe_imports() method in Fickling's static analyzer fails to flag several high-risk Pyth | Jan 10, 2026 | 7.8 | 25 | NO | NO |
CVE-2026-22608HIGH Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, both ctypes and pydoc modules aren't explicitly blocked. Even other existing pickle scanning t | Jan 10, 2026 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trailofbits.
Media articles that mention a CVE ID that affects a product developed by Trailofbits — matched by CVE ID, not by vendor name.