CVE-2026-56304Disclosure(mmaitre314 / picklescan)

LOWCVSS 6.9 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte files via logging.FileHandler class instantiation. Attackers can exploit this by crafting malicious pickle payloads to bypass RCE blocklists and create lock files or other filesystem artifacts, potentially causing denial of service or application disruption.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • picklescan

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
picklescan

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-20: 3Technical Details · 2026-06-20: 306-20
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-56304 Unsafe Pickle Deserialization in picklescan Before 1.0.1 Enables Arbitrary File Creation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56304

    Post summary

    CVE-2026-56304 is a newly disclosed vulnerability where unsafe pickle deserialization in picklescan before 1.0.1 allows arbitrary file creation.

    0000040
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-56304 picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte files via logging.Fil… https://www.cve.org/CVERecord?id=CVE-2026-56304 ----- Traducción: CVE-2026-56304 pic… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑56304, noting that picklescan versions before 1.0.1 contain an unsafe pickle deserialization flaw that allows unauthenticated attackers to create arbitrary zero‑byte files, and links to the official CVE record.

    0000026
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-56304 picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte files via logging.Fil… https://www.cve.org/CVERecord?id=CVE-2026-56304

    Post summary

    This post provides a brief disclosure of CVE-2026-56304, detailing the unsafe pickle deserialization flaw that allows unauthenticated creation of arbitrary zero‑byte files.

    00000251
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmmaitre314picklescan---

Explore more