CVE-2026-25632Patch(waterfutures / epyt-flow)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch waterfutures epyt-flow systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. This vulnerability is fixed in 0.16.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • epyt-flow

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-02-06); latest day: 1
  • 6 total mentions across 2 days

Affected systems

Products
epyt-flow

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-02-06: 5Mentions · 2026-02-07: 1Patch / Workaround · 2026-02-06: 2Patch / Workaround · 2026-02-07: 1Technical Details · 2026-02-06: 3Technical Details · 2026-02-07: 102-0602-07
Signal classification3 categories
Patch
350.0%
Disclosure
233.3%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-065
Disclosure2General1Patch2
2026-02-071
Patch1
Full discourse6 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25632 - Critical EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow’s REST API parses ... https://www.thehackerwire.com/vulnerability/CVE-2026-25632/ https://t.co/xdq2L1Pj80

    Post summary

    A new CVE-2026-25632 affecting EPyT‑Flow’s REST API has been announced with a critical severity rating, but the post lacks technical or remediation details.

    10010119
    113 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-25632 in WaterFutures EPyT-Flow (<0.16.1) lets attackers execute OS commands via malicious JSON. Immediate upgrade to 0.16.1+ is essential! Secure your water infrastructure now. https://radar.offseq.com/threat/cve-2026-25632-cwe-502-deserialization-of-untr... https://t.co/n8Yapc6CvH

    Post summary

    The tweet alerts that CVE‑2026‑25632 in WaterFutures EPyT‑Flow allows OS command execution via malicious JSON and urges an immediate upgrade to version 0.16.1+.

    0000052
    268 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25632: CRITICAL] Prior to version 0.16.1, EPyT-Flow had a vulnerability in the REST API allowing attacker-controlled JSON request bodies to execute OS commands. Update to 0.16.1 for a fix.#cve,CVE-2026-25632,#cybersecurity https://cvefind.com/CVE-2026-25632

    Post summary

    The tweet announces a critical vulnerability in EPyT‑Flow’s REST API that permits remote command execution via JSON payloads and recommends updating to version 0.16.1 to apply the fix.

    0000053
    583 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-25632 EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow… https://www.cve.org/CVERecord?id=CVE-2026-25632

    Post summary

    The text references CVE-2026-25632 affecting EPyT-Flow but provides only a brief package description and a link to the CVE record, with no exploitation or mitigation details.

    00000177
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25632: EPyT-Flow has unsafe JSON deseri... Classic __type__ deserialization flaw in EPyT-Flow yields trivial RCE via subprocess.Popen - critical risk for water di... https://zerodaysignal.com/vulnerability/CVE-2026-25632 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The text announces CVE-2026-25632, describing a __type__ deserialization vulnerability in EPyT-Flow that enables trivial RCE through subprocess.Popen and poses a critical risk.

    0000065
    132 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    EPyT-Flow contains an unsafe JSON deserialization vulnerability (CVE-2026-25632) allowing potential code execution. Update to 0.16.1. #EPyTFlow #Deserialization #AppSec https://www.pulsepatch.io/posts/cve-2026-25632-epyt-flow-unsafe-json-deserialization

    Post summary

    The post announces an unsafe JSON deserialization vulnerability in EPyT-Flow (CVE-2026-25632) that could allow code execution, and recommends updating to version 0.16.1.

    0000071
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwaterfuturesepyt-flow-python-

Explore more