Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2, Schema.load(data, many=True) is vulnerable to denial of service attacks. A moderately sized request can consume a disproportionate amount of CPU time. This issue has been patched in version 3.26.2 and 4.1.2.

Project Subscriptions

Vendors Products
Marshmallow Project Subscribe
Marshmallow Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-428g-f7cq-pgp5 Marshmallow has DoS in Schema.load(many)
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 23 Dec 2025 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Marshmallow Project
Marshmallow Project marshmallow
Vendors & Products Marshmallow Project
Marshmallow Project marshmallow

Tue, 23 Dec 2025 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 22 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 22 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
Description Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2, Schema.load(data, many=True) is vulnerable to denial of service attacks. A moderately sized request can consume a disproportionate amount of CPU time. This issue has been patched in version 3.26.2 and 4.1.2.
Title Marshmallow has DoS in Schema.load(many)
Weaknesses CWE-405
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-22T21:35:02.469Z

Reserved: 2025-12-18T18:29:07.309Z

Link: CVE-2025-68480

cve-icon Vulnrichment

Updated: 2025-12-22T21:34:55.509Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-22T22:16:09.457

Modified: 2025-12-23T14:51:52.650

Link: CVE-2025-68480

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-12-22T21:20:15Z

Links: CVE-2025-68480 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-12-23T22:39:52Z

Weaknesses