CVE-2026-22612: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-22612 is a detection bypass vulnerability in Fickling, a Python pickling decompiler and static analyzer developed by Trail of Bits. The flaw, dubbed "builtins blindness," allows attackers to craft malicious pickle files that evade Fickling's security analysis by exploiting the tool's failure to emit AST import nodes for Python's builtins module. All versions prior to 0.1.7 are affected. It was disclosed on January 9–10, 2026, and carries a CVSS v3.1 score of 7.8 (High) and a CVSS v4.0 score of 8.9 (High) (GitHub Advisory).

Technical details

The root cause (CWE-502: Deserialization of Untrusted Data) lies in fickling/fickle.py, where the run() method of the Global opcode handler explicitly skipped emitting AST ImportFrom nodes when the module was __builtin__, __builtins__, or builtins. Because Fickling's security analysis operates on the generated AST rather than raw bytecode, imports from builtins — including dangerous functions like __import__ and getattr — were invisible to the scanner. An attacker could craft a pickle payload that uses builtins.__import__ to load os, then builtins.getattr to retrieve os.system, and execute arbitrary commands, while Fickling's analysis classified the payload as LIKELY_SAFE. A secondary technique using the BUILD opcode satisfied data-flow liveness checks, further preventing detection (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an attacker to bypass Fickling's security validation and deliver malicious pickle payloads to systems that rely on Fickling to screen untrusted serialized Python objects. Once a malicious pickle is loaded by the target application, arbitrary code execution is achievable, leading to full compromise of confidentiality, integrity, and availability of the affected system. This is particularly dangerous in ML/AI pipelines and data processing workflows where pickle files from untrusted sources are routinely scanned with tools like Fickling before being deserialized (GitHub Advisory).

Exploitability

A proof-of-concept payload generator (poc.py) is publicly documented in the GitHub security advisory, demonstrating how to craft a raw_bypass.pkl file that executes arbitrary OS commands while being classified as LIKELY_SAFE by vulnerable Fickling versions. There is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.043%, reflecting low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).

Exploitation steps

  1. Craft the malicious pickle payload: Using the publicly documented PoC approach, construct a pickle byte sequence that uses GLOBAL opcodes referencing builtins.__import__ and builtins.getattr to load os.system without triggering Fickling's import detection.
  2. Evade data-flow analysis: Use the BUILD opcode to incorporate the result of os.system() (the exit code) into a returned Exception object's state, creating a logical dependency chain that satisfies Fickling's liveness heuristics and prevents "UNUSED" variable warnings.
  3. Submit the payload for scanning: Present the crafted raw_bypass.pkl file to a system or pipeline that uses a vulnerable version of Fickling (< 0.1.7) to validate pickle files before deserialization. Fickling will classify the payload as LIKELY_SAFE.
  4. Trigger deserialization: Once the payload passes Fickling's validation, it is deserialized by the target Python application, executing the embedded os.system('whoami') (or any attacker-chosen command) with the privileges of the application process (GitHub Advisory).

Indicators of compromise

  • File System: Presence of .pkl files containing builtins\n__import__\n or builtins\ngetattr\n byte sequences in raw form; unexpected pickle files classified as LIKELY_SAFE by Fickling that reference os, subprocess, or other sensitive modules.
  • Logs: Application logs showing deserialization of pickle files followed by unexpected process spawning or network connections; Fickling scan results returning LIKELY_SAFE for files that subsequently trigger anomalous behavior.
  • Process: Unusual child processes spawned by Python interpreter processes (e.g., sh, bash, cmd.exe, whoami, curl, wget) immediately after pickle deserialization events.
  • Network: Outbound connections from Python application processes to unexpected external hosts following pickle file processing (GitHub Advisory).

Mitigation and workarounds

Upgrade Fickling to version 0.1.7 or later, which fixes the issue by removing the special-case exclusion for builtins imports and ensuring AST ImportFrom nodes are emitted for all modules, including builtins (Patch Commit, v0.1.7 Release). If immediate patching is not possible, avoid using Fickling to validate untrusted pickle files and restrict access to any pipeline that deserializes externally sourced pickle data. Additionally, review any systems that processed untrusted pickle files with vulnerable Fickling versions for signs of compromise.

Community reactions

The vulnerability was reported by security researcher 0x-Apollyon and acknowledged by Trail of Bits maintainer thomas-chauchefoin-tob, who published the advisory and patch on January 9, 2026. The fix was bundled with four other bypass fixes in the v0.1.7 release, indicating a broader security review of Fickling's analysis pipeline (v0.1.7 Release). No significant broader media coverage or social media discussion beyond the GitHub advisory has been identified.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management