SCA: security update for python-socketio (GHSA-g8c6-8fjj-2r4m)

medium Tenable Cloud Security Plugin ID 435521

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code
execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary
Python code through malicious pickle deserialization in multi-server deployments on which the attacker
previously gained access to the message queue that the servers use for internal communications. When
Socket.IO servers are configured to use a message queue backend such as Redis for inter-server
communication, messages sent between the servers are encoded using the `pickle` Python module. When a
server receives one of these messages through the message queue, it assumes it is trusted and immediately
deserializes it. The vulnerability stems from deserialization of messages using Python's `pickle.loads()`
function. Having previously obtained access to the message queue, the attacker can send a python-socketio
server a crafted pickle payload that executes arbitrary code during deserialization via Python's
`__reduce__` method. This vulnerability only affects deployments with a compromised message queue. The
attack can lead to the attacker executing random code in the context of, and with the privileges of a
Socket.IO server process. Single-server systems that do not use a message queue, and multi-server systems
with a secure message queue are not vulnerable. In addition to making sure standard security practices are
followed in the deployment of the message queue, users of the python-socketio package can upgrade to
version 5.14.0 or newer, which remove the `pickle` module and use the much safer JSON encoding for inter-
server messaging. (CVE-2025-61765)

See Also

https://github.com/advisories/GHSA-g8c6-8fjj-2r4m

Plugin Details

Severity: Medium

ID: 435521

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 10/7/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.5

Percentile: 57.44

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.9

Temporal Score: 5.1

Vector: CVSS2#AV:A/AC:L/Au:M/C:C/I:C/A:P

CVSS Score Source: CVE-2025-61765

CVSS v3

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 5.6

Vector: CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/7/2025

Vulnerability Publication Date: 10/6/2025

Reference Information

CVE: CVE-2025-61765

cwe: CWE-502