13
submitted 3 hours ago by mina86@lemmy.wtf to c/python@programming.dev

It is common knowledge that pickle is a serious security risk. And yet, vulnerabilities involving that serialisation format keep happening. In the article I shortly describe the issue and appeal to people to stop using pickle.

top 1 comments
sorted by: hot top controversial new old
[-] danielquinn@lemmy.ca 4 points 3 hours ago

The thing is, none of the suggested alternatives can do what pickle does, and the article focuses on a narrow (albeit ubiquitous) use case: serialisation of untrusted data.

There are still legitimate use cases for pickle, especially when storing, caching, or comparing objects that can't easily be serialised with say, JSON or TOML. It's a question of using the right thing for the right job is all, and pretending like JSON is a computable alternative to pickle doesn't help anyone.

this post was submitted on 10 Feb 2026
13 points (84.2% liked)

Python

7750 readers
4 users here now

Welcome to the Python community on the programming.dev Lemmy instance!

📅 Events

PastNovember 2023

October 2023

July 2023

August 2023

September 2023

🐍 Python project:
💓 Python Community:
✨ Python Ecosystem:
🌌 Fediverse
Communities
Projects
Feeds

founded 2 years ago
MODERATORS