CVE-2026-26210: Python Pickle Loads On Zmq Recv

Untrusted bytes received from a ZMQ socket are passed to pickle.loads(), which deserializes attacker-controlled data and enables arbitrary code execution via pickle's __reduce__ machinery (CWE-502). The ZMQ socket provides no authentication by default, so any network-reachable peer can send a malicious pickle payload. Replace pickle with a safe format (JSON,

Provally CuratedPublic repositoryHighHigh confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-26210-python-pickle-loads-on-zmq-recv --engine opengrep

Description

Untrusted bytes received from a ZMQ socket are passed to pickle.loads(), which deserializes attacker-controlled data and enables arbitrary code execution via pickle's __reduce__ machinery (CWE-502). The ZMQ socket provides no authentication by default, so any network-reachable peer can send a malicious pickle payload. Replace pickle with a safe format (JSON,