Junglewise Threat Intelligence

CVE-2026-31048: irmen Pyro3 remote code execution via pickle deserialization

CVE-2026-31048 · Severity: critical · CVSS 9.8 · Published 2026-04-13

Executive brief

Pyro3 is a legacy Python library used for building distributed applications where objects can communicate over a network. A critical vulnerability allows unauthenticated attackers to execute arbitrary commands on the server by sending a specially crafted message. This could lead to a total system compromise, data theft, or service disruption.

Technical details

The vulnerability is a deserialization of untrusted data (CWE-502) within the Pyro 3.x protocol handler. The library invokes `pickle.loads()` on incoming serialized message data without performing prior authentication or integrity checks. Because the Python pickle format allows for arbitrary object reconstruction via callables like `__reduce__`, an attacker can craft a payload that executes arbitrary code upon deserialization. This affects all versions of the legacy Pyro 3.x branch. No patch is available as the project is archived; users are advised to migrate to Pyro5 or restrict network access to trusted channels.

Affected products

  • irmen Pyro3 <= 3.16

Timeline

  • 2026-04-10: advisory: Initial security advisory published by Sif-0x01
  • 2026-04-13: disclosed: CVE-2026-31048 assigned and published

References