CVE-2026-25359: Rascals Pendulum

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Deserialization of Untrusted Data vulnerability in rascals Pendulum pendulum allows Object Injection.This issue affects Pendulum: from n/a through < 3.1.5.

Affected products

  • Rascals Pendulum: up to and including 3.1.5

Published 2026-03-25. Last modified 2026-06-17.