CVE-2025-68480Medium
ANC
ANC
Anchore Vulnerability Database overrides
Supplementary feed layered on top of upstream sources. Anchore maintainers publish override records to suppress known false positives and fill CPE/PURL gaps that would otherwise cause Grype and similar scanners to mis-report a system.
Region
US
Updates
6 ч
License
Apache-2.0
Curated corrections to the Anchore/Grype vulnerability database: false-positive suppressions, missing CPE mappings and distro-specific backport fixes.
https://github.com/anchore/grype-db →Share link
Anyone with the link can open this vulnerability.
Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to befor…
CVSS
5.3
Medium
EPSS
0.00
p28
Published
2025-01-01
Updated
2025-01-01
Description
Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2, Schema.load(data, many=True) is vulnerable to denial of service attacks. A moderately sized request can consume a disproportionate amount of CPU time. This issue has been patched in version 3.26.2 and 4.1.2.
Tags · CWE
Pre-auth
CWE-405
CWE-405ClassIncomplete
Asymmetric Resource Consumption (Amplification)
The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."
https://cwe.mitre.org/data/definitions/405.html →Open in CWE collection →Affected products
Python-marshmallowPython-marshmallowPython-marshmallowPython-marshmallowPython-marshmallow
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Timeline
2025-01-01
Published
2025-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: L
Low (L)
Exploit indicators
EPSS
0.001 · p28
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
| Product | Vendor | Status |
|---|---|---|
| Tracked | ||
| python-marshmallow | Tracked | |
| python-marshmallow | Tracked | |
| python-marshmallow | Tracked | |
| python-marshmallow | Tracked | |
| python-marshmallow | Tracked |
Source databases
ANC
ANC
Anchore Vulnerability Database overrides
Supplementary feed layered on top of upstream sources. Anchore maintainers publish override records to suppress known false positives and fill CPE/PURL gaps that would otherwise cause Grype and similar scanners to mis-report a system.
Region
US
Updates
6 ч
License
Apache-2.0
Curated corrections to the Anchore/Grype vulnerability database: false-positive suppressions, missing CPE mappings and distro-specific backport fixes.
https://github.com/anchore/grype-db →DEB
DEB
Debian Security Advisories (DSA)
DSAs are published by the Debian Security Team for issues affecting the stable distribution. The downstream tracker (security-tracker.debian.org) additionally maps every CVE to its package-level status across all supported suites.
Region
Intl.
Updates
1 ч
License
Public Domain
Advisories covering the Debian stable and oldstable releases. Ship notes include the exact .deb version that remediates each issue.
https://www.debian.org/security/ →UBU
UBU
Ubuntu Security Notices (USN)
USNs are authoritative for Ubuntu systems. The CVE Tracker links each vulnerability to its per-release status (needed, released, not-affected) and to the exact Launchpad bug where the fix is integrated.
Region
Intl.
Updates
1 ч
License
CC BY-SA 3.0
Security notices for Ubuntu LTS and interim releases, covering main, universe and (via Pro) ESM-extended packages.
https://ubuntu.com/security/notices →External references
https://github.com/marshmallow-code/marshmallow/commit/d24a0c9df061c4daa92f71cf85aca25b83eee508@https://github.com/marshmallow-code/marshmallow/security/advisories/GHSA-428g-f7cq-pgp5https://www.cve.org/CVERecord?id=CVE-2025-68480@https://github.com/marshmallow-code/marshmallow/security/advisories/GHSA-428g-f7cq-pgp5@https://github.com/marshmallow-code/marshmallow/commit/218d98a785d3bd25dad8880bb07e9cce70340f31 (4.1.2)@https://github.com/marshmallow-code/marshmallow/commit/70141f4180fb94ced3544cdefdaff89172dd3956 (4.1.2)@https://github.com/marshmallow-code/marshmallow/commit/36f87877d0e889e682386a0121eabe030cde57b1 (4.1.2)@https://github.com/marshmallow-code/marshmallow/commit/0356a3f1c307830f8ded56d823abca5611c594c9 (3.26.2)@https://github.com/marshmallow-code/marshmallow/commit/6d4a17dad54ea9711040c6aa6ba4d59267242a41 (3.26.2)@https://github.com/marshmallow-code/marshmallow/commit/489a8d421dc7955bb53b89e962d69465fbc5b6af (3.26.2)@https://github.com/marshmallow-code/marshmallow/commit/d24a0c9df061c4daa92f71cf85aca25b83eee508