Description
Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2, Schema.load(data, many=True) is vulnerable to denial of service attacks. A moderately sized request can consume a disproportionate amount of CPU time. This issue has been patched in version 3.26.2 and 4.1.2.
Published: 2025-12-22
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-428g-f7cq-pgp5 Marshmallow has DoS in Schema.load(many)
Ubuntu USN Ubuntu USN USN-8225-1 Python marshmallow vulnerabilities
History

Tue, 23 Dec 2025 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Marshmallow Project
Marshmallow Project marshmallow
Vendors & Products Marshmallow Project
Marshmallow Project marshmallow

Tue, 23 Dec 2025 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 22 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 22 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
Description Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2, Schema.load(data, many=True) is vulnerable to denial of service attacks. A moderately sized request can consume a disproportionate amount of CPU time. This issue has been patched in version 3.26.2 and 4.1.2.
Title Marshmallow has DoS in Schema.load(many)
Weaknesses CWE-405
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Marshmallow Project Marshmallow
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-22T21:35:02.469Z

Reserved: 2025-12-18T18:29:07.309Z

Link: CVE-2025-68480

cve-icon Vulnrichment

Updated: 2025-12-22T21:34:55.509Z

cve-icon NVD

Status : Deferred

Published: 2025-12-22T22:16:09.457

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-68480

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-12-22T21:20:15Z

Links: CVE-2025-68480 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-12-23T22:39:52Z

Weaknesses