PT-2025-42814 · Orjson+2 · Orjson+2

Published

2025-10-20

·

Updated

2025-10-21

·

CVE-2025-61301

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions CAPEv2 versions prior to commit 52e4b43 on 2025-05-17
Description The software contains a flaw that allows attackers who can submit samples to cause incomplete or missing behavioral analysis reports. This occurs by generating deeply nested or oversized behavior data that triggers MongoDB BSON limits or orjson recursion errors when a sample executes within the sandbox environment. The issue affects the reporting/mongodb.py and reporting/jsondump.py components.
Recommendations Update to CAPEv2 commit 52e4b43 or a later version.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-61301

Affected Products

Capev2
Mongodb
Orjson