← Vulnerability feed

Vulnerability record · CVE-2018-8021 · published 7 November 2018

CVE-2018-8021: Apache Superset pickle deserialization remote code execution

Apache · Superset

Apache Superset versions prior to 0.23 deserialized data with an unsafe pickle load method, allowing untrusted serialized data to be executed as code. Because the flaw is reachable over the network without credentials, it exposes pre-0.23 deployments to full remote code execution.

9.8 CVSS 3.0 Critical EPSS 53% · top 1.1% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.0 base score, v2 7.5
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network, unauthenticated, no-interaction exploitation, public exploit code and a high EPSS score make this a critical pre-auth RCE for unpatched Superset deployments.

What it is

Apache Superset versions prior to 0.23 deserialized data with an unsafe pickle load method, allowing untrusted serialized data to be executed as code. Because the flaw is reachable over the network without credentials, it exposes pre-0.23 deployments to full remote code execution.

Impact

An attacker can execute arbitrary code on the Superset server, leading to complete compromise of confidentiality, integrity and availability of the host and its data.

Attack surface

The CVSS vector is network-reachable with no privileges and no user interaction, so the vulnerable deserialization path can be hit directly by an unauthenticated remote request. The description does not specify the exact endpoint or parameter involved.

Exploitation

CVE-2018-8021 is not listed in CISA KEV, but an Exploit-DB entry exists and EPSS gives a 30-day probability of about 0.53 (98.9th percentile), indicating public exploit code and elevated likelihood of exploitation.

What to do

  • Upgrade Superset to 0.23 or later, which replaced the unsafe pickle load method; note 0.23 predates the Apache Software Foundation releases.
  • If immediate upgrade is not possible, restrict network access to the Superset web interface to trusted networks only.
  • Search the codebase and any custom integrations for pickle.load or pickle.loads usage and replace with a safe serialization format.
  • Monitor for and block requests attempting to submit serialized pickle payloads to Superset endpoints.
  • Treat any pre-0.23 Superset instance as potentially compromised and review logs for unexpected process execution.

Detection

  • Review Superset access logs for anomalous POST or GET requests to endpoints that handle serialized data, especially from unexpected source IPs.
  • Monitor for child processes spawned by the Superset web service, such as shells or interpreters, which would indicate code execution.
  • Alert on outbound network connections from the Superset host to unfamiliar destinations following web requests.
  • Inventory deployed Superset versions and flag any instance running below 0.23.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/apache/incubator-superset/pull/4243 PatchThird Party Advisory
https://www.exploit-db.com/exploits/45933/ ExploitThird Party AdvisoryVDB Entry
https://github.com/apache/incubator-superset/pull/4243 PatchThird Party Advisory
https://www.exploit-db.com/exploits/45933/ ExploitThird Party AdvisoryVDB Entry

Track CVE-2018-8021 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27524Apache Superset default SECRET_KEY allows session forgery and auth bypassApache Superset versions up to and including 2.0.1 ship with a default SECRET_KEY that, if left unchanged, lets an attacker forge signed session cook…KEVEPSS 97%analysed9.8CVE-2024-39887Apache superset sql injection vulnerabilityAn SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certa…EPSS 4.4%9.8CVE-2022-27479Apache superset sql injection vulnerabilityApache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.EPSS 2.9%8.8CVE-2023-49736Apache superset sql injection vulnerabilityA where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Sup…EPSS 1.2%8.8CVE-2023-40610Apache superset incorrect authorization vulnerabilityImproper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database conn…EPSS 1.3%8.8CVE-2022-43719Apache superset cross-site request forgery vulnerabilityTwo legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset versio…EPSS 0.57%8.8CVE-2021-41971Apache superset sql injection vulnerabilityApache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malic…EPSS 1.8%8.8CVE-2020-13948Apache superset vulnerabilityWhile investigating a bug report on Apache Superset, it was determined that an authenticated user could craft requests via a number of templated text…EPSS 3.1%

Source: NIST National Vulnerability Database (record CVE-2018-8021), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.