Pypi · Marshmallow · CVE-2025-68480
**Name of the Vulnerable Software and Affected Versions**
Marshmallow versions 3.0.0rc1 through 3.26.1
Marshmallow versions 4.0.0 through 4.1.1
**Description**
Marshmallow, a library for converting complex objects to and from simple Python datatypes, contains a flaw in the `Schema.load(data, many=True)` method. A moderately sized request can cause excessive CPU usage, leading to a denial of service.
**Recommendations**
Update to Marshmallow version 3.26.2 or later.
Update to Marshmallow version 4.1.2 or later.