Asymmetric Resource Consumption (Amplification) Affecting marshmallow package, versions [3.0.0rc1,3.26.2)[4.0.0,4.1.2)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.26% (18th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-MARSHMALLOW-14550833
  • published23 Dec 2025
  • disclosed22 Dec 2025
  • credit카푸치노

Introduced: 22 Dec 2025

CVE-2025-68480  (opens in a new tab)
CWE-405  (opens in a new tab)

How to fix?

Upgrade marshmallow to version 3.26.2, 4.1.2 or higher.

Overview

Affected versions of this package are vulnerable to Asymmetric Resource Consumption (Amplification) via the Schema.load method of the error storage utility, when handling input with the many parameter set to True. An attacker can cause excessive CPU consumption by submitting a moderately sized request.

Workaround

This vulnerability can be mitigated by validating the input type before processing, such as ensuring the data is a list and failing fast if it is not.

References

CVSS Base Scores

version 4.0
version 3.1