GHSA-538v-3wq9-4h3r · Severity: critical · Ecosystem: pip — Apache Pyfory python is vulnerable to deserialization of untrusted data
Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows arbitrary code execution. An application is vulnerable if it reads pyfory serialized data from untrusted sources. An attacker can craft a data stream that selects pickle-fallback serializer during deserialization, leading to the execution of `pickle.loads`, which is vulnerable to remote code execution. Users are recommended to upgrade to pyfory version 0.12.3 or later, which has removed pickle fallback serializer and thus fixes this issue.
Conclusion & alert: CVE-2025-61622 is rated Moderate Risk (61.6/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.46%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-07 | 0.43% | 0.46% | +0.02% |
| 2 | 2026-03-21 | 0.29% | 0.43% | +0.14% |
| 3 | 2026-02-28 | — | 0.29% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-538v-3wq9-4h3r · Severity: critical · Ecosystem: pip — Apache Pyfory python is vulnerable to deserialization of untrusted data
| URL | Tags |
|---|---|
| https://lists.apache.org/thread/vfn9hp9qt06db5yo1gmj3l114o3o2csd | Issue Tracking Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/09/29/3 | Mailing List Third Party Advisory |