Junglewise Threat Intelligence

CVE-2026-33155: DeepDiff memory exhaustion DoS in _RestrictedUnpickler

CVE-2026-33155 · Severity: high · CVSS 4 · Published 2026-03-18

Vendors: PyPI.

Executive brief

DeepDiff is a Python library used to find and apply differences between data structures. A vulnerability in how it handles serialized data allows an attacker to send a very small, specially crafted file that forces the application to consume massive amounts of memory (over 10GB). This results in a denial-of-service (DoS) by crashing the application or the server it is running on.

Technical details

The vulnerability is an uncontrolled resource consumption (CWE-400) issue within DeepDiff's `_RestrictedUnpickler`. While the unpickler validates which classes can be loaded via `SAFE_TO_IMPORT`, it fails to validate or limit the arguments passed to their constructors during the `REDUCE` opcode. An attacker can provide a small pickle payload that calls constructors for types like `builtins.bytes` or `builtins.list` with extremely large integer arguments, leading to massive memory allocation. This can be triggered either during direct `pickle_load` calls or during the application of a `Delta` object where `type_changes` are processed without size guards. The issue is fixed in version 8.6.2.

Affected products

  • qlustered deepdiff >= 5.0.0, <= 8.6.1

Timeline

  • 2026-03-18: advisory: GitHub Advisory published
  • 2026-03-18: patched: Fix released in version 8.6.2
  • 2026-03-20: other: NVD published CVE-2026-33155

References

Related threats