CVE-2025-68480: Marshmallow has DoS in Schema.load(many)
(updated )
Schema.load(data, many=True) is vulnerable to denial of service attacks. A moderately sized request can consume a disproportionate amount of CPU time.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-68480 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →