CVE-2026-14534General(trailofbits / fickling)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch trailofbits fickling systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS denylist (fickle.py). Because these modules are absent from the denylist, fickling's check_safety() function returns LIKELY_SAFE with zero findings for pickle payloads that invoke dangerous functions including _posixsubprocess.fork_exec (C-level process spawner capable of executing arbitrary binaries), site.execsitecustomize (executes arbitrary site customization code), and atexit._run_exitfuncs (triggers all registered exit handler callbacks). The fickling.load() API chains check_safety() into pickle.loads() as an explicit security gate; a LIKELY_SAFE verdict causes the payload to be deserialized and executed. This shares the same root cause as CVE-2026-22607 (cProfile), CVE-2025-67748 (pty), and CVE-2025-67747 (marshal/types). OvertlyBadEvals does not flag these modules because they are standard library imports. UnsafeImports does not flag them because they are not in the denylist. The UnusedVariables heuristic is defeated by the SETITEMS opcode pattern.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fickling

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-07-04); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
fickling

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-07-04: 3Mentions · 2026-07-07: 1Patch / Workaround · 2026-07-04: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-07-04: 2Technical Details · 2026-07-07: 107-0407-07
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-07-043
Disclosure1General2
2026-07-071
Patch1
Full discourse4 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-14534 (CVSS 8.8) Trail of Bits fickling ≤0.1.10 bypass allows arbitrary code execution via unsafe Python stdlib modules (_posixsubprocess, site, atexit). check_safety() returns false negative. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/r5S6fmMUlL

    Post summary

    The tweet alerts users to high‑severity CVE‑2026‑14534, a Python runtime flaw that permits arbitrary code execution, and urges immediate patching.

    0001055
    66 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Unsafe pickle safety bypass via missing UNSAFE_IMPORTS entries (CVE-2026-14534) Trail of Bits fickling through 0.1.10 fails to include key Python stdlib modules (_posixsubprocess, site, atexit) in its UNSAFE_IMPORTS denylist, impacting check_safety() and downstream fickling.load() decisions. The root cause is improper input validation/allowlist-denylist logic that underestimates risk when analyzing pickle opcode imports. An attacker can supply a crafted malicious pickle that check_safety() incorrectly rates as LIKELY_SAFE, causing applications that rely on fickling.load() to deserialize it, typically requiring only that the victim processes untrusted pickle content. Successful exploitation can lead to arbitrary code execution by invoking dangerous functions like _posixsubprocess.fork_exec, site.execsitecustomize, or atexit._run_exitfuncs. 👉 Affected: fickling <= 0.1.10 | Upgrade to No fix yet — treat as suspicious

    Post summary

    The post announces CVE‑2026‑14534, explaining how unsafe pickle imports in fickling can lead to arbitrary code execution, advises upgrading as a precaution, but does not provide a PoC, exploit code, or evidence of active exploitation.

    0000061
    236 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-14534 Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS… https://www.cve.org/CVERecord?id=CVE-2026-14534 ----- Traducción: CVE-2026-14534 Tra… http://infoflow.cloud`

    Post summary

    The tweet briefly references CVE‑2026‑14534, stating that Trail of Bits versions up to 0.1.10 exclude specific Python standard library modules from UNSAFE_IMPORTS, and includes a link to the CVE record, but provides no further detail.

    0000029
    91 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-14534 Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS… https://www.cve.org/CVERecord?id=CVE-2026-14534

    Post summary

    The post lists a CVE and technical detail about excluded modules but lacks evidence of exploitation, PoC, or patches.

    00000780
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptrailofbitsfickling-python-

Explore more