CVE-2026-22606·Python vulnerability
Fickling is a Python pickling decompiler and static analyzer. Fickling versions up to and including 0.1.6 do not treat Python’s runpy module as unsafe. Because of this, a malicious pickle that uses runpy.run_path() or runpy.run_module() is classified as SUSPICIOUS instead of OVERTLY_MALICIOUS. If a user relies on Fickling’s output to decide whether a pickle is safe to deserialize, this misclassification can lead them to execute attacker-controlled code on their system. This affects any workflow or product that uses Fickling as a security gate for pickle deserialization. This issue has been patched in version 0.1.7.
- Severity
- high
- Software
- Python
- Fixed in
- 0.1.7
- Published
- 2026-01-10
Affected versions
Until: 0.1.7
Fixed in: 0.1.7
How to fix this CVE
Update the Fickling library to version 0.1.7 or later to ensure that the runpy module is correctly classified as a malicious code execution vector. If your application or security pipeline relies on Fickling for pickle safety validation, this update is critical to prevent acceptance of weaponized pickle files that could execute arbitrary code during deserialization.
sudo dnf update python3-ficklingDefensia detects this vulnerability
How to check if you are affected
- Check the installed Fickling version: python3 -c 'import fickling; print(fickling.__version__)'
- Verify if Fickling is in use: grep -r 'from fickling' /your/app/directory or pip3 show fickling | grep Version
- Search application logs for pickle deserialization operations: grep -i 'pickle\|deserialize\|runpy' /var/log/application.log
- Confirm the fix by re-running the version check after update and verifying output shows 0.1.7 or higher
FAQ
What is CVE-2026-22606?
CVE-2026-22606 is a security classification bypass in Fickling, a pickle security analyzer, where the runpy module is not properly flagged as malicious code execution. This allows attackers to craft pickle files that bypass Fickling's safety checks and execute arbitrary code when deserialized.
Is CVE-2026-22606 being actively exploited?
No, there are no confirmed reports of active exploitation in the wild, and no public exploits have been released. However, the vulnerability poses a high risk to organizations using Fickling as a security control.
What versions of Python are affected by CVE-2026-22606?
The vulnerability affects Fickling versions up to and including 0.1.6. Fickling 0.1.7 and later contain the fix. The underlying Python interpreter versions are not the primary factor—vulnerability depends on Fickling library version.
How do I check if my server is vulnerable to CVE-2026-22606?
Run: python3 -c 'import fickling; print(fickling.__version__)'. If the version is 0.1.6 or earlier, you are vulnerable. You can also check: pip3 show fickling | grep -i version
Does Defensia detect CVE-2026-22606?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Fickling is installed on a monitored server, CVE-2026-22606 will appear in your dashboard with remediation steps.
Related Python CVEs
References
- https://github.com/trailofbits/fickling/commit/9a2b3f89bd0598b528d62c10a64c1986fcb09f66
- https://github.com/trailofbits/fickling/releases/tag/v0.1.7
- https://github.com/trailofbits/fickling/security/advisories/GHSA-wfq2-52f7-7qvj
- https://github.com/trailofbits/fickling/security/advisories/GHSA-wfq2-52f7-7qvj
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-22606. Free for 1 server.
Get started free