Skip to content
Critical Security Flaw in python-diskcache Affects Fedora Users

Critical Security Flaw in python-diskcache Affects Fedora Users

First seen 24 Mar 2026, 05:15 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 25, 2026 at 04:45 UTC
  • •CVE-2025-69872 allows arbitrary code execution through insecure pickle deserialization.
  • •Affected systems include Fedora 43 and Fedora 44 using python-diskcache.
  • •Users must update to version 5.6.4-12 or later to mitigate the vulnerability.

A significant security vulnerability, CVE-2025-69872, has been identified in the python-diskcache library, which is utilized in Fedora systems. This flaw allows for arbitrary code execution via insecure pickle deserialization, posing a serious risk to users. The vulnerability was published on 2026-02-11, and a patch has been incorporated by developer Sam Doran as of March 15, 2026. Users are advised to update their systems to mitigate the risk of exploitation. The affected versions include python-diskcache prior to 5.6.4-12. Both Fedora 43 and Fedora 44 are impacted by this vulnerability. The update can be applied using the dnf package manager. Failure to update may leave systems vulnerable to potential attacks exploiting this flaw.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 197d ago How this analysis works

Timeline

2026-02-11
CVE-2025-69872 published
2026-03-15
Patch incorporated by Sam Doran
2026-03-24
Articles published detailing the vulnerability and patch

More articles in this cluster (3)

Following this threat?

Track Fedora and CVE-2025-69872 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed