CVE-2022-35411 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 45.7% (pctl 99)
Patch early
A public exploit exists.
Description
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 45.72% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-522 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2022-07-08 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| rpc.py project | rpc.py |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | rpc.py 0.6.0 - Remote Code Execution (RCE) | 2022-07-29 |
References
- http://packetstormsecurity.com/files/167872/rpc.py-0.6.0-Remote-Code-Execution.html
- https://github.com/abersheeran/rpc.py/commit/491e7a841ed9a754796d6ab047a9fb16e23bf8bd
- https://github.com/ehtec/rpcpy-exploit
- https://medium.com/%40elias.hohl/remote-code-execution-0-day-in-rpc-py-709c76690c30
- http://packetstormsecurity.com/files/167872/rpc.py-0.6.0-Remote-Code-Execution.html
- https://github.com/abersheeran/rpc.py/commit/491e7a841ed9a754796d6ab047a9fb16e23bf8bd
- https://github.com/ehtec/rpcpy-exploit
- https://medium.com/%40elias.hohl/remote-code-execution-0-day-in-rpc-py-709c76690c30
→ the Explorer · watch your stack · NVD