Launchpad.net

CVE 2016-4000

Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.

See the CVE page on Mitre.org for more details.