Skip to content

Commit

Permalink
bpo-37977: Warn more strongly and clearly about pickle security (GH-1…
Browse files Browse the repository at this point in the history
  • Loading branch information
lordmauve authored and rhettinger committed Aug 31, 2019
1 parent 013e52f commit daa82d0
Show file tree
Hide file tree
Showing 2 changed files with 19 additions and 4 deletions.
22 changes: 18 additions & 4 deletions Doc/library/pickle.rst
Original file line number Diff line number Diff line change
Expand Up @@ -30,9 +30,17 @@ avoid confusion, the terms used here are "pickling" and "unpickling".

.. warning::

The :mod:`pickle` module is not secure against erroneous or maliciously
constructed data. Never unpickle data received from an untrusted or
unauthenticated source.
The ``pickle`` module **is not secure**. Only unpickle data you trust.

It is possible to construct malicious pickle data which will **execute
arbitrary code during unpickling**. Never unpickle data that could have come
from an untrusted source, or that could have been tampered with.

Consider signing data with :mod:`hmac` if you need to ensure that it has not
been tampered with.

Safer serialization formats such as :mod:`json` may be more appropriate if
you are processing untrusted data. See :ref:`comparison-with-json`.


Relationship to other Python modules
Expand Down Expand Up @@ -75,6 +83,9 @@ The :mod:`pickle` module differs from :mod:`marshal` in several significant ways
pickling and unpickling code deals with Python 2 to Python 3 type differences
if your data is crossing that unique breaking change language boundary.


.. _comparison-with-json:

Comparison with ``json``
^^^^^^^^^^^^^^^^^^^^^^^^

Expand All @@ -94,7 +105,10 @@ There are fundamental differences between the pickle protocols and
types, and no custom classes; pickle can represent an extremely large
number of Python types (many of them automatically, by clever usage
of Python's introspection facilities; complex cases can be tackled by
implementing :ref:`specific object APIs <pickle-inst>`).
implementing :ref:`specific object APIs <pickle-inst>`);

* Unlike pickle, deserializing untrusted JSON does not in itself create an
arbitrary code execution vulnerability.

.. seealso::
The :mod:`json` module: a standard library module allowing JSON
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Warn more strongly and clearly about pickle insecurity

0 comments on commit daa82d0

Please sign in to comment.