CVE-2026-20251: How a Validator Short-Circuit Turns Splunk's KV Store into an RCE Gateway
A deep dive into the jsonpickle deserialization chain in Splunk Secure Gateway 3.9.19 — and why safe=True isn't.
Tags: Security, CVE, Python, Splunk, Vulnerability Research
During a white-box vulner
blog.reactivezero.com5 min read