CVE-2026-33155Disclosure(qluster / deepdiff)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

DeepDiff is a project focused on Deep Difference and search of any Python data. From version 5.0.0 to before version 8.6.2, the pickle unpickler _RestrictedUnpickler validates which classes can be loaded but does not limit their constructor arguments. A few of the types in SAFE_TO_IMPORT have constructors that allocate memory proportional to their input (builtins.bytes, builtins.list, builtins.range). A 40-byte pickle payload can force 10+ GB of memory, which crashes applications that load delta objects or call pickle_load with untrusted data. This issue has been patched in version 8.6.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • deepdiff

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-19); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
deepdiff

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-19: 2Mentions · 2026-03-20: 1Mentions · 2026-03-21: 1Technical Details · 2026-03-19: 2Technical Details · 2026-03-20: 1Technical Details · 2026-03-21: 103-1903-2003-21
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-192
Disclosure2
2026-03-201
General1
2026-03-211
Disclosure1
Full discourse4 posts
  • Security Harvester@secharvesterx
    Disclosure

    we found a memory exhaustion CVE in a library downloaded 29 million times a month. AWS, DataHub, and Lightning AI are in the blast radius. https://www.periphery.security/blog/cve-2026-33155---40-bytes-to-chaos https://t.co/D8EHHfEQ4F

    Post summary

    The post announces a newly discovered memory exhaustion vulnerability in a widely‑used library, but does not provide PoC, exploit code, active exploitation evidence, or a patch announcement.

    01011144
    793 followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    we found a memory exhaustion CVE in a library downloaded 29 million times a month. AWS, DataHub, and Lightning AI are in the blast radius. https://www.periphery.security/blog/cve-2026-33155---40-bytes-to-chaos

    Post summary

    The tweet announces the discovery of a memory exhaustion vulnerability (CVE‑2026‑33155) in a widely‑used library, underscoring its potential impact on several high‑profile cloud services, without providing exploitation details or mitigation guidance.

    00003552
    32.9K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33155 DeepDiff is a project focused on Deep Difference and search of any Python data. From version 5.0.0 to before version 8.6.2, the pickle unpickler _RestrictedUnpickler … https://www.cve.org/CVERecord?id=CVE-2026-33155

    Post summary

    The post announces CVE‑2026‑33155, describing a pickle unpickler vulnerability in DeepDiff versions 5.0.0 up to before 8.6.2, without providing PoC, exploit code, or patch information.

    00000169
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33155 - DeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORT Intel Report: https://ift.tt/MUFld6Z

    Post summary

    An alert announcing CVE‑2026‑33155 causes memory exhaustion DoS in DeepDiff, with no PoC, exploit, patch, or active exploitation details provided.

    0000040
    334 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appqlusterdeepdiff---

Explore more