python-diskcache: python-diskcache: Arbitrary code execution via insecure pickle deserialization
Published Feb 11, 2026
5.2
MEDIUMCVSS 4.0
EPSS 0.54%
Description
DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.
Affected products
No data.
No data.
No data.
Red Hat OpenShift AI 3.3
rhoai/odh-kserve-agent-rhel9:1770754605
Fixed · RHSA-2026:3713
Red Hat Satellite 6.18
satellite/foreman-mcp-server-rhel9:1782739344
Fixed · RHSA-2026:36350
Red Hat AI Inference Server
rhaiis-preview/vllm-cuda-rhel9
Affected
Red Hat AI Inference Server
rhaiis/vllm-cuda-rhel9
Not affected
Red Hat AI Inference Server
rhaiis/vllm-rocm-rhel9
Not affected
Red Hat AI Inference Server
rhaiis/vllm-spyre-rhel9
Affected
Red Hat AI Inference Server
rhaiis/vllm-tpu-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-aws-cuda-rhel9
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-azure-cuda-rhel9
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gcp-cuda-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-controller-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-router-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-storage-initializer-rhel9
Will not fix
Red Hat OpenShift AI (RHOAI)
rhoai/odh-llama-stack-core-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-trustyai-ragas-lls-provider-dsp-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-vllm-cpu-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-vllm-cuda-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-vllm-gaudi-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-vllm-rocm-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift AI 3.3 | rhoai/odh-kserve-agent-rhel9:1770754605 | Fixed | RHSA-2026:3713 |
| Red Hat Satellite 6.18 | satellite/foreman-mcp-server-rhel9:1782739344 | Fixed | RHSA-2026:36350 |
| Red Hat AI Inference Server | rhaiis-preview/vllm-cuda-rhel9 | Affected | n/a |
| Red Hat AI Inference Server | rhaiis/vllm-cuda-rhel9 | Not affected | n/a |
| Red Hat AI Inference Server | rhaiis/vllm-rocm-rhel9 | Not affected | n/a |
| Red Hat AI Inference Server | rhaiis/vllm-spyre-rhel9 | Affected | n/a |
| Red Hat AI Inference Server | rhaiis/vllm-tpu-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-aws-cuda-rhel9 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-azure-cuda-rhel9 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gcp-cuda-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-controller-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-router-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-storage-initializer-rhel9 | Will not fix | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-llama-stack-core-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-trustyai-ragas-lls-provider-dsp-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-vllm-cpu-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-vllm-cuda-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-vllm-gaudi-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-vllm-rocm-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat products are not affected by this flaw in their default state. Multiple default parameters would need to be altered in order for this flaw to exploitable. Products that make use of vLLM would need to be configured to use the `outlines` backend, a specific environmental variable in the vLLM process namespace would need to be set and the attacker would need to have access to the restricted cache directory. Red Hat customers who do not alter these values are not at risk.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (11)
- https://access.redhat.com/errata/RHSA-2026:36350
- https://access.redhat.com/errata/RHSA-2026:3713
- https://access.redhat.com/security/cve/CVE-2025-69872 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2439059 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-207391 Advisory
- https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69872-DiskCache-Pickle-Deserialization.md
- https://github.com/advisories/GHSA-w8v5-vhqr-4h9v Advisory
- https://github.com/grantjenks/python-diskcache
- https://nvd.nist.gov/vuln/detail/CVE-2025-69872
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69872.json
- https://www.cve.org/CVERecord?id=CVE-2025-69872
Change history (0)
No recorded changes yet.