CVE-2026-31235: Python Pickle Loads On Multiprocessing Queue Data

Calling pickle.loads() on bytes obtained from a multiprocessing/queue Queue is unsafe. Any process or thread able to write to the queue can inject a malicious pickle payload whose __reduce__ executes arbitrary code in the consumer process. Replace pickle with a safe serializer (e.g., JSON, MessagePack with strict schemas) or authenticate the payload (HMAC) b

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-31235-python-pickle-loads-on-multiprocessing-queue-data --engine opengrep

Description

Calling pickle.loads() on bytes obtained from a multiprocessing/queue Queue is unsafe. Any process or thread able to write to the queue can inject a malicious pickle payload whose __reduce__ executes arbitrary code in the consumer process. Replace pickle with a safe serializer (e.g., JSON, MessagePack with strict schemas) or authenticate the payload (HMAC) b