Critical severity9.8NVD Advisory· Published Feb 11, 2026· Updated Jul 15, 2026
CVE-2025-69872
CVE-2025-69872
Description
DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
diskcachePyPI | <= 5.6.3 | — |
Affected products
5- osv-coords4 versionspkg:apk/chainguard/nemopkg:apk/chainguard/vllm-cuda-13.2pkg:apk/chainguard/vllm-openai-cuda-13.0pkg:pypi/diskcache
< 2.7.3-r0+ 3 more
- (no CPE)range: < 2.7.3-r0
- (no CPE)range: < 0.26.0-r0
- (no CPE)range: < 0.26.0-r0
- (no CPE)range: <= 5.6.3
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-w8v5-vhqr-4h9vghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-69872ghsaADVISORY
- github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69872-DiskCache-Pickle-Deserialization.mdnvdWEB
- access.redhat.com/errata/RHSA-2026:36350nvd
- access.redhat.com/errata/RHSA-2026:3713nvd
- access.redhat.com/security/cve/CVE-2025-69872nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69872.jsonnvd
News mentions
0No linked articles in our index yet.