A thread-safety vulnerability in PyO3 exposed Rust applications embedding or extending Python to possible data races through pyo3::types::PyCFunction::new_closure and the temporary companion new_closure_bound. In affected 0.21-0.22 releases, closures supplied to those APIs were required to implement Send + 'static but not Sync, even though the resulting Python-callable object could be invoked from multiple Python threads through a shared reference. That gap allowed unsafe concurrent access to captured non-Sync types such as Cell and RefCell, creating a path to violate Rust’s aliasing and thread-safety guarantees.
The flaw affects all Python versions, but the risk is higher in free-threaded Python environments introduced by PEP 703 because execution is no longer serialized by the Global Interpreter Lock. Even in GIL-protected Python, concurrent or interleaved execution could still occur when code temporarily detaches from the interpreter, including through Python::allow_threads. PyO3 addressed the issue in version 0.29.0 by adding a Sync bound to closures accepted by new_closure and updating tests to use thread-safe primitives such as AtomicI32 instead of RefCell.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-11, a RustSec advisory disclosed a thread-safety vulnerability in PyO3 affecting `PyCFunction::new_closure` and the temporary complement `new_closure_bound` in the 0.21–0.22 series. The advisory warned that missing `Sync` bounds could allow concurrent closure execution and data races across Python threads.
PyO3 addressed a thread-safety flaw in `pyo3::types::PyCFunction::new_closure` by requiring closures to implement both `Send` and `Sync`. The fix was released in PyO3 version 0.29.0, and related test code was updated to use thread-safe primitives.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcerustsec.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.