rpc.py
An fast and powerful RPC framework based on ASGI/WSGI.
Activity
- Latest release
- 4y ago
- Total releases
- 12
- Cadence
- ~19 days
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Jul 16, 2020
| Version | Released | |
|---|---|---|
0.6.0
minor
1 CVE
CVE-2022-35411
PYSEC-2026-526
GHSA-8rq8-f485-7v8x
Jun 29, 2026
rpc.py vulnerable to Deserialization of Untrusted Data
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle. Per the maintainer, rpc.py is not designed for an API that is open to the outside world, and external requests cannot reach rpc.py in real world use. A fix exists on the
Affected versions
0.4.2
0.4.3
0.5.0
0.5.1
0.6.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.1
patch
1 CVE
CVE-2022-35411
PYSEC-2026-526
GHSA-8rq8-f485-7v8x
Jun 29, 2026
rpc.py vulnerable to Deserialization of Untrusted Data
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle. Per the maintainer, rpc.py is not designed for an API that is open to the outside world, and external requests cannot reach rpc.py in real world use. A fix exists on the
Affected versions
0.4.2
0.4.3
0.5.0
0.5.1
0.6.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2022-35411
PYSEC-2026-526
GHSA-8rq8-f485-7v8x
Jun 29, 2026
rpc.py vulnerable to Deserialization of Untrusted Data
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle. Per the maintainer, rpc.py is not designed for an API that is open to the outside world, and external requests cannot reach rpc.py in real world use. A fix exists on the
Affected versions
0.4.2
0.4.3
0.5.0
0.5.1
0.6.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.4.3
patch
1 CVE
CVE-2022-35411
PYSEC-2026-526
GHSA-8rq8-f485-7v8x
Jun 29, 2026
rpc.py vulnerable to Deserialization of Untrusted Data
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle. Per the maintainer, rpc.py is not designed for an API that is open to the outside world, and external requests cannot reach rpc.py in real world use. A fix exists on the
Affected versions
0.4.2
0.4.3
0.5.0
0.5.1
0.6.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.4.2
patch
1 CVE
CVE-2022-35411
PYSEC-2026-526
GHSA-8rq8-f485-7v8x
Jun 29, 2026
rpc.py vulnerable to Deserialization of Untrusted Data
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle. Per the maintainer, rpc.py is not designed for an API that is open to the outside world, and external requests cannot reach rpc.py in real world use. A fix exists on the
Affected versions
0.4.2
0.4.3
0.5.0
0.5.1
0.6.0
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.4.1
patch
| ||
0.4.0
minor
| ||
0.3.1
patch
| ||
0.3.0
minor
| ||
0.2.2
patch
| ||
0.2.1
minor
| ||
0.1.1
initial
|