Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, Fickling is vulnerable to detection bypass due to "builtins" blindness. This issue has been patched in version 0.1.7.
References
Configurations
History
16 Jan 2026, 18:56
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| First Time |
Trailofbits
Trailofbits fickling |
|
| CPE | cpe:2.3:a:trailofbits:fickling:*:*:*:*:*:python:*:* | |
| References | () https://github.com/trailofbits/fickling/commit/9f309ab834797f280cb5143a2f6f987579fa7cdf - Patch | |
| References | () https://github.com/trailofbits/fickling/releases/tag/v0.1.7 - Release Notes | |
| References | () https://github.com/trailofbits/fickling/security/advisories/GHSA-h4rm-mm56-xf63 - Vendor Advisory |
12 Jan 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/trailofbits/fickling/security/advisories/GHSA-h4rm-mm56-xf63 - |
10 Jan 2026, 02:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-10 02:15
Updated : 2026-01-16 18:56
NVD link : CVE-2026-22612
Mitre link : CVE-2026-22612
CVE.ORG link : CVE-2026-22612
JSON object : View
Products Affected
trailofbits
- fickling
CWE
CWE-502
Deserialization of Untrusted Data
