PT-2026-41945 · Pypi · Apscheduler

·

CVE-2026-31072

·

Published

2026-05-19

·

Updated

2026-07-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions APScheduler (affected versions not specified)
Description The JSONSerializer and CBORSerializer are subject to Remote Code Execution (RCE) through insecure deserialization. The unmarshal object() function enables arbitrary class instantiation and state injection by dynamically importing modules and calling setstate on any class present in the Python environment. This can be triggered by submitting a specially crafted JSON or CBOR payload to an application utilizing these serializers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31072
GHSA-9CFW-F3F9-7MM7
PYSEC-2026-282

Affected Products

Apscheduler