Improperly Controlled Modification of Dynamically-Determined Object Attributes in deepdiff - CVE-2025-58367
Published: July 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the Delta class when processing user-controlled input passed to the constructor. A remote attacker can supply crafted Delta data to modify deepdiff.serialization.SAFE_TO_IMPORT and trigger unsafe pickle deserialization to execute arbitrary code.
Only applications that pass untrusted user input directly into Delta are affected. Exploitation can use bytes input directly, and dictionary input may also be exploitable depending on the application.
Affected software
Fedora
openSUSE Leap
python-orderly-set
python311-deepdiff
python-deepdiff
How to mitigate CVE-2025-58367
python-orderly-set - addressed in versions 5.5.0-2.fc41, 5.5.0-2.fc42
python311-deepdiff - update to 6.3.0-150600.3.3.1
python-deepdiff - addressed in versions 8.6.1-1.el10_1, 8.6.1-1.el10_2, 8.6.1-1.fc41, 8.6.1-1.fc42
External References
Related Security Bulletins
- Improperly Controlled Modification of Dynamically-Determined Object Attributes in deepdiff
- Fedora EPEL 10.1 update for python-deepdiff
- Fedora EPEL 10.2 update for python-deepdiff
- Fedora 41 update for python-deepdiff, python-orderly-set
- Fedora 42 update for python-deepdiff, python-orderly-set
- SUSE update for python-deepdiff