{"id":"UBUNTU-CVE-2025-68480","details":"Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2, Schema.load(data, many=True) is vulnerable to denial of service attacks. A moderately sized request can consume a disproportionate amount of CPU time. This issue has been patched in version 3.26.2 and 4.1.2.","modified":"2026-04-30T09:57:11.928731Z","published":"2025-12-22T22:16:00Z","related":["USN-8225-1"],"upstream":["CVE-2025-68480"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-68480"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-68480"},{"type":"REPORT","url":"https://github.com/marshmallow-code/marshmallow/security/advisories/GHSA-428g-f7cq-pgp5"},{"type":"REPORT","url":"https://github.com/marshmallow-code/marshmallow/commit/218d98a785d3bd25dad8880bb07e9cce70340f31"},{"type":"REPORT","url":"https://github.com/marshmallow-code/marshmallow/commit/70141f4180fb94ced3544cdefdaff89172dd3956"},{"type":"REPORT","url":"https://github.com/marshmallow-code/marshmallow/commit/36f87877d0e889e682386a0121eabe030cde57b1"},{"type":"REPORT","url":"https://github.com/marshmallow-code/marshmallow/commit/0356a3f1c307830f8ded56d823abca5611c594c9"},{"type":"REPORT","url":"https://github.com/marshmallow-code/marshmallow/commit/6d4a17dad54ea9711040c6aa6ba4d59267242a41"},{"type":"REPORT","url":"https://github.com/marshmallow-code/marshmallow/commit/489a8d421dc7955bb53b89e962d69465fbc5b6af"},{"type":"REPORT","url":"https://github.com/marshmallow-code/marshmallow/commit/d24a0c9df061c4daa92f71cf85aca25b83eee508"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8225-1"}],"affected":[{"package":{"name":"python-marshmallow","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/python-marshmallow@3.4.0-1ubuntu0.1~esm1?arch=source&distro=esm-apps/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.0-1ubuntu0.1~esm1"}]}],"versions":["3.0.0b14-1","3.2.1-1","3.2.2-1","3.3.0-1","3.4.0-1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"python3-marshmallow","binary_version":"3.4.0-1ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-68480.json"}},{"package":{"name":"python-marshmallow","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/python-marshmallow@3.13.0-1ubuntu0.1~esm1?arch=source&distro=esm-apps/jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.13.0-1ubuntu0.1~esm1"}]}],"versions":["3.10.0-1","3.13.0-1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"python3-marshmallow","binary_version":"3.13.0-1ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-68480.json"}},{"package":{"name":"python-marshmallow","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/python-marshmallow@3.20.1-1.1ubuntu0.1~esm1?arch=source&distro=esm-apps/noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.20.1-1.1ubuntu0.1~esm1"}]}],"versions":["3.18.0-1","3.20.1-1.1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"python3-marshmallow","binary_version":"3.20.1-1.1ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-68480.json"}},{"package":{"name":"python-marshmallow","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/python-marshmallow@3.26.1-0.2?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.26.1-0.2"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-marshmallow","binary_version":"3.26.1-0.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-68480.json"}},{"package":{"name":"python-marshmallow","ecosystem":"Ubuntu:Pro:26.04:LTS","purl":"pkg:deb/ubuntu/python-marshmallow@3.26.1-0.4ubuntu0.1~esm1?arch=source&distro=esm-apps/resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.26.1-0.4ubuntu0.1~esm1"}]}],"versions":["3.26.1-0.2","3.26.1-0.3","3.26.1-0.4"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"python3-marshmallow","binary_version":"3.26.1-0.4ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-68480.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}]}