GHSL-2025-115: Insecure deserialization in NVTabular could lead to RCE - CVE-2025-33214
Published Aug 8, 2026
·Updated
NVTabular v23.08.00 is affected by an insecure deserialization vulnerability in the Workflow.load method, which could allow an attacker to execute arbitrary code.
Affected Software
1 affected component
NVTabular=23.08.00
Event History
Aug 8, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of GHSL-2025-115?
GHSL-2025-115 has a risk rating of 80, indicating a high severity level.
2
What vulnerability does GHSL-2025-115 describe?
GHSL-2025-115 describes an insecure deserialization vulnerability in NVTabular that could lead to remote code execution.
3
How do I fix GHSL-2025-115?
To fix GHSL-2025-115, ensure you update NVTabular to the latest version that addresses the insecure deserialization issue.
4
What versions of NVTabular are affected by GHSL-2025-115?
GHSL-2025-115 affects NVTabular version 23.08.00.
5
What could an attacker achieve by exploiting GHSL-2025-115?
An attacker exploiting GHSL-2025-115 could execute arbitrary code on the affected system.