Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-67221

Опубликовано: 22 янв. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

The orjson.dumps function in orjson thru 3.11.4 does not limit recursion for deeply nested JSON documents.

A flaw was found in orjson. The orjson.dumps function does not properly limit recursion when processing deeply nested JSON documents. A remote attacker could exploit this vulnerability by providing a specially crafted JSON document, leading to a Denial of Service (DoS) condition.

Отчет

For this flaw to be remotely exploitable, the system must accept data from untrusted users. For that reason, our analysis indicates the attack vector for this flaw is "Local".

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-minimal-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-minimal-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-supported-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-supported-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-dellemc-openmanage-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-minimal-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-minimal-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-supported-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-supported-rhel9Fix deferred

Показывать по

Дополнительная информация

https://bugzilla.redhat.com/show_bug.cgi?id=2432074orjson: orjson: Denial of Service due to unbounded recursion with deeply nested JSON documents

EPSS

Процентиль: 7%
0.00025
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
2 месяца назад

The orjson.dumps function in orjson thru 3.11.4 does not limit recursion for deeply nested JSON documents.

suse-cvrf
17 дней назад

Security update for python-orjson

github
2 месяца назад

orjson does not limit recursion for deeply nested JSON documents

EPSS

Процентиль: 7%
0.00025
Низкий

5.5 Medium

CVSS3