CVE-2026-25632·Python vulnerability
EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. This vulnerability is fixed in 0.16.1.
- Severity
- critical
- Software
- Python
- Fixed in
- 0.16.1
- Published
- 2026-02-06
Affected versions
Until: 0.16.1
Fixed in: 0.16.1
How to fix this CVE
Update EPyT-Flow to version 0.16.1 or later to patch the insecure JSON deserialization vulnerability. This vulnerability allows arbitrary code execution through malicious JSON payloads with crafted type fields. If you use EPyT-Flow in production, prioritize this update immediately given the critical CVSS 10.0 rating.
sudo dnf update python3-epyt-flow || pip3 install --upgrade epyt-flow>=0.16.1Defensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST|GET request containing JSON with '"type":"subprocess.Popen"' or similar dangerous class instantiation patterns in request body; HTTP requests to EPyT-Flow REST API endpoints with 'args' or 'kwargs' fields paired with OS-level class referencesWAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Block HTTP requests to EPyT-Flow REST API endpoints containing JSON bodies with 'type' field set to known dangerous classes (subprocess, os, sys, eval, exec, __import__); implement strict Content-Type validation and JSON schema validation requiring absence of 'type' fields in untrusted inputsHow to check if you are affected
- Check installed EPyT-Flow version: pip3 show epyt-flow | grep Version
- Verify if EPyT-Flow REST API is exposed: netstat -tlnp | grep -E ':(5000|8000|8080)' and check application logs for REST endpoint listeners
- Search application logs for suspicious JSON payloads with 'type' field and class instantiation attempts: grep -r '"type".*subprocess\|"type".*Popen\|"type".*os\.' /var/log/
- Confirm patched version is running: pip3 show epyt-flow | grep Version && python3 -c 'import epyt_flow; print(epyt_flow.__version__)' to verify version >= 0.16.1
FAQ
What is CVE-2026-25632?
CVE-2026-25632 is a critical remote code execution vulnerability in EPyT-Flow's JSON deserialization logic that allows attackers to instantiate arbitrary Python classes and execute system commands by including a malicious 'type' field in JSON requests or files sent to the REST API.
Is CVE-2026-25632 being actively exploited?
No, this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public exploits have been disclosed, though the critical nature of the flaw makes it a high-priority target for attackers.
What versions of Python are affected by CVE-2026-25632?
All versions of EPyT-Flow prior to 0.16.1 are affected. The vulnerability exists in the custom JSON deserializer (my_load_from_json) used by the REST API and JSON file loading functions.
How do I check if my server is vulnerable to CVE-2026-25632?
Run 'pip3 show epyt-flow | grep Version' and verify the version is 0.16.1 or higher. If the version is below 0.16.1, your system is vulnerable.
Does Defensia detect CVE-2026-25632?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If EPyT-Flow is installed on a monitored server, CVE-2026-25632 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-25632. Free for 1 server.
Get started free