UBUNTU-CVE-2025-68480
Dashboard / Vulnerabilities / UBUNTU-CVE-2025-68480
UBUNTU-CVE-2025-68480
Summary:
Details: Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2, Schema.load(data, many=True) is vulnerable to denial of service attacks. A moderately sized request can consume a disproportionate amount of CPU time. This issue has been patched in version 3.26.2 and 4.1.2.
References: https://ubuntu.com/security/CVE-2025-68480, https://www.cve.org/CVERecord?id=CVE-2025-68480, https://github.com/marshmallow-code/marshmallow/security/advisories/GHSA-428g-f7cq-pgp5, https://github.com/marshmallow-code/marshmallow/commit/218d98a785d3bd25dad8880bb07e9cce70340f31, https://github.com/marshmallow-code/marshmallow/commit/70141f4180fb94ced3544cdefdaff89172dd3956, https://github.com/marshmallow-code/marshmallow/commit/36f87877d0e889e682386a0121eabe030cde57b1, https://github.com/marshmallow-code/marshmallow/commit/0356a3f1c307830f8ded56d823abca5611c594c9, https://github.com/marshmallow-code/marshmallow/commit/6d4a17dad54ea9711040c6aa6ba4d59267242a41, https://github.com/marshmallow-code/marshmallow/commit/489a8d421dc7955bb53b89e962d69465fbc5b6af, https://github.com/marshmallow-code/marshmallow/commit/d24a0c9df061c4daa92f71cf85aca25b83eee508, https://ubuntu.com/security/notices/USN-8225-1
Affected packages
Package
Name: python-marshmallow
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/focal
Affected ranges
Type: ECOSYSTEM
Events:
