PT-2024-21907 · Orjson · Orjson
David Buchanan
·
Published
2024-02-25
·
Updated
2025-09-18
·
CVE-2024-27454
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
orjson versions prior to 3.9.15
Description
The issue is related to the
orjson.loads function in orjson, which does not limit recursion for deeply nested JSON documents. This can lead to potential exploitation.Recommendations
For versions prior to 3.9.15, update to version 3.9.15 or later to resolve the issue. As a temporary workaround, consider restricting the use of deeply nested JSON documents until a patch is applied.
Exploit
Fix
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Orjson