CVE-2026-27794: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-27794 is a Remote Code Execution (RCE) vulnerability in LangGraph Checkpoint's caching layer, classified as "LangGraph BaseCache Deserialization of Untrusted Data." It affects langgraph-checkpoint versions prior to 4.0.0 and was disclosed on February 23–25, 2026. The vulnerability stems from unsafe pickle deserialization when cache backends inheriting from BaseCache are explicitly enabled and nodes opt into caching via CachePolicy. It carries a CVSS v3.1 base score of 6.6 (Medium), assigned by GitHub as the CNA (GitHub Advisory, Red Hat CVE).

Technical details

The root cause (CWE-502: Deserialization of Untrusted Data) lies in BaseCache defaulting to JsonPlusSerializer(pickle_fallback=True) in libs/checkpoint/langgraph/cache/base/__init__.py. When msgpack serialization fails, the JsonPlusSerializer.loads_typed() method in libs/checkpoint/langgraph/checkpoint/serde/jsonplus.py falls back to pickle.loads(data_) for entries stored as a ("pickle", ...) tuple. An attacker who can write a crafted pickle payload to the cache backend (e.g., Redis, SQLite, or in-memory cache) will trigger arbitrary code execution when the LangGraph process reads and deserializes that entry. Exploitation requires three preconditions: (1) the application explicitly enables a cache backend, (2) at least one node opts into caching via CachePolicy, and (3) the attacker has write access to the cache storage layer — making this a post-compromise escalation vector (GitHub Advisory, Patch PR).

Impact

Successful exploitation results in arbitrary code execution with the privileges of the LangGraph process, yielding full confidentiality, integrity, and availability compromise of the affected host. Attack scenarios include injecting malicious payloads into a network-accessible Redis instance with weak or no authentication, exploiting shared multi-tenant cache infrastructure, or writing to a writable SQLite cache file. Beyond direct process compromise, attackers may exfiltrate sensitive data processed by the LangGraph application, tamper with cached inference results, disrupt service availability, and potentially pivot laterally within the infrastructure (GitHub Advisory, Feedly).

Exploitability

A proof-of-concept exploit was published by Trend Micro's Zero Day Initiative (ZDI-26-135) on March 3, 2026, referenced under ZDI-CAN-28385 (ZDI Advisory). The vulnerability was discovered and reported by Peter Girnus (@gothburz), Demeng Chen, and Brandon Niemczyk of Trend Micro ZDI (GitHub Advisory). There is no current evidence of in-the-wild exploitation, and the CVE is not listed in the CISA KEV catalog. The EPSS score is approximately 0.32%, reflecting low but non-negligible exploitation probability given the PoC availability (Feedly).

Exploitation steps

  1. Identify a vulnerable deployment: Confirm the target application uses langgraph-checkpoint < 4.0.0, has explicitly enabled a cache backend (e.g., RedisCache, SqliteCache, or InMemoryCache passed to StateGraph.compile(cache=...)), and has at least one node configured with CachePolicy.
  2. Gain write access to the cache backend: Identify a network-accessible Redis instance with weak or no authentication, a shared cache service reachable from another tenant, or a writable SQLite cache file with permissive file permissions.
  3. Craft a malicious pickle payload: Generate a Python pickle payload that executes arbitrary commands upon deserialization, e.g., using pickle.dumps() with a custom __reduce__ method that spawns a reverse shell or executes a system command.
  4. Format the payload for LangGraph's serializer: Wrap the pickle bytes in the format expected by JsonPlusSerializer — specifically as a ("pickle", <base64-encoded-pickle-bytes>) tuple — so that loads_typed() routes it to pickle.loads().
  5. Write the payload to the cache backend: Insert the crafted entry into the Redis keyspace (e.g., via redis-cli SET <langgraph-cache-key> <payload>) or write it to the SQLite cache file at the appropriate key.
  6. Trigger deserialization: Wait for or trigger a LangGraph graph execution that causes the process to read the poisoned cache entry. The loads_typed() function will call pickle.loads() on the attacker-controlled bytes, executing the embedded payload with the privileges of the LangGraph process (GitHub Advisory, ZDI Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the LangGraph process to external IPs or C2 infrastructure following graph execution; anomalous Redis SET commands from unauthorized clients writing to LangGraph cache keyspaces.
  • Cache Storage: Redis keys in LangGraph cache namespaces containing binary data with pickle magic bytes (\x80\x04 or \x80\x05) rather than expected JSON/msgpack content; SQLite cache files modified by unexpected users or processes.
  • Process: Unusual child processes spawned by the Python/LangGraph process (e.g., /bin/sh, bash, curl, wget, python3) not consistent with normal graph execution; unexpected network connections initiated by the LangGraph service account.
  • Logs: Application logs showing deserialization errors or unexpected pickle type entries being processed by JsonPlusSerializer; Redis access logs showing SET operations from unexpected source IPs or service accounts.
  • File System: New files, scripts, or cron jobs created by the LangGraph process user; unexpected modifications to SQLite cache files (*.db) in the application's working directory.

Mitigation and workarounds

The primary remediation is to upgrade langgraph-checkpoint to version 4.0.0 or later, which changes the BaseCache default serializer to JsonPlusSerializer(pickle_fallback=False), eliminating the unsafe deserialization path (GitHub Release, Patch PR). If immediate patching is not possible, disable caching entirely by not passing cache=... to StateGraph.compile() or any other BaseCache configuration. Additionally, harden cache backend access controls: enforce strong authentication on Redis instances, restrict network access to cache services, apply strict file permissions on SQLite cache files, and isolate cache infrastructure between tenants. IBM has also released fixes for affected products including IBM Cloud Pak for Business Automation (April 2026 iFixes) and IBM watsonx Orchestrate Developer Edition (IBM CP4BA Advisory, IBM watsonx Advisory).

Community reactions

The vulnerability was credited to researchers Peter Girnus (@gothburz), Demeng Chen, and Brandon Niemczyk from Trend Micro's Zero Day Initiative, who published advisory ZDI-26-135 on March 3, 2026 (ZDI Advisory). Red Hat tracked the issue and IBM issued security bulletins addressing the vulnerability across multiple enterprise products in April–May 2026 (Red Hat CVE, IBM CP4BA Advisory). The fix was straightforward — a one-line change flipping pickle_fallback from True to False — and was merged into the LangGraph main branch on January 12, 2026, prior to public disclosure (Patch PR).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management