Executive brief
Pyro3 is a legacy Python library used for building distributed applications where objects can communicate over a network. A critical vulnerability allows unauthenticated attackers to execute arbitrary commands on the server by sending a specially crafted message. This could lead to a total system compromise, data theft, or service disruption.
Technical details
The vulnerability is a deserialization of untrusted data (CWE-502) within the Pyro 3.x protocol handler. The library invokes `pickle.loads()` on incoming serialized message data without performing prior authentication or integrity checks. Because the Python pickle format allows for arbitrary object reconstruction via callables like `__reduce__`, an attacker can craft a payload that executes arbitrary code upon deserialization. This affects all versions of the legacy Pyro 3.x branch. No patch is available as the project is archived; users are advised to migrate to Pyro5 or restrict network access to trusted channels.
Affected products
- irmen Pyro3 <= 3.16
Timeline
- 2026-04-10: advisory: Initial security advisory published by Sif-0x01
- 2026-04-13: disclosed: CVE-2026-31048 assigned and published