PT-2025-52725 · Pypi+3 · Marshmallow+3

·

CVE-2025-68480

·

Published

2025-12-22

·

Updated

2026-07-13

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Marshmallow versions 3.0.0rc1 through 3.26.1 Marshmallow versions 4.0.0 through 4.1.1
Description Marshmallow, a library for converting complex objects to and from simple Python datatypes, contains a flaw in the Schema.load(data, many=True) method. A moderately sized request can cause excessive CPU usage, leading to a denial of service.
Recommendations Update to Marshmallow version 3.26.2 or later. Update to Marshmallow version 4.1.2 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AN24336
CLEANSTART-2026-FU07345
CLEANSTART-2026-KE11953
CLEANSTART-2026-NM83456
CLEANSTART-2026-QE89118
CVE-2025-68480
ECHO-A840-85C8-68AC
GHSA-428G-F7CQ-PGP5
OPENSUSE-SU-2026:10003-1
OPENSUSE-SU-2026:20087-1
PYSEC-2026-1605
SUSE-SU-2026:0226-1
SUSE-SU-2026:20130-1
USN-8225-1

Affected Products

Debian
Linuxmint
Marshmallow
Ubuntu