Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-31072

Опубликовано: 19 мая 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object function allows for arbitrary class instantiation and state injection by dynamically importing modules and calling setstate on any class available in the Python environment. An attacker can exploit this by submitting a specially crafted JSON or CBOR payload to an application using these serializers

A flaw was found in APScheduler, affecting its JSONSerializer and CBORSerializer components. This vulnerability, known as insecure deserialization, allows a remote attacker to execute arbitrary code on the system. By sending a specially crafted data payload, an attacker can manipulate the application to run malicious commands, potentially leading to a complete compromise of the affected system.

Отчет

Despite the CVEORG report of this vulnerability, the affected deserializers are only present in 4.x versions of APScheduler. Red Hat does not ship the affected versions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-tech-preview/metrics-service-rhel9Not affected
Red Hat OpenStack Platform 18.0python-APSchedulerNot affected
Red Hat Quay 3quay/quay-rhel8Not affected
Red Hat Quay 3quay/quay-rhel9Not affected
Red Hat Satellite 6satellite/iop-advisor-backend-rhel9Not affected
Red Hat Satellite 6satellite/iop-host-inventory-rhel9Not affected
Red Hat Satellite 6satellite/iop-vmaas-rhel9Not affected
Red Hat Satellite 6satellite/iop-vulnerability-engine-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2479907apscheduler: APScheduler: Remote Code Execution via Insecure Deserialization

EPSS

Процентиль: 53%
0.0081
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
3 месяца назад

The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object function allows for arbitrary class instantiation and state injection by dynamically importing modules and calling __setstate__ on any class available in the Python environment. An attacker can exploit this by submitting a specially crafted JSON or CBOR payload to an application using these serializers

CVSS3: 9.8
nvd
3 месяца назад

The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object function allows for arbitrary class instantiation and state injection by dynamically importing modules and calling __setstate__ on any class available in the Python environment. An attacker can exploit this by submitting a specially crafted JSON or CBOR payload to an application using these serializers

CVSS3: 9.8
debian
3 месяца назад

The JSONSerializer and CBORSerializer in APScheduler (all versions inc ...

CVSS3: 9.8
github
3 месяца назад

APScheduler's JSONSerializer and CBORSerializer are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization

EPSS

Процентиль: 53%
0.0081
Низкий

8.8 High

CVSS3