Asymmetric Resource Consumption (Amplification) in marshmallow - CVE-2025-68480

 

Asymmetric Resource Consumption (Amplification) in marshmallow - CVE-2025-68480

Published: March 5, 2026


Vulnerability identifier: #VU123562
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-68480
CWE-ID: CWE-405
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a moderately sized request can consume a disproportionate amount of CPU time. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

marshmallow
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Public Cloud Module
openSUSE Leap
openEuler
watsonx Code Assistant On Prem
python311-marshmallow
python-marshmallow
python-marshmallow-help
python3-marshmallow

How to mitigate CVE-2025-68480

Install updates from vendor's website.

marshmallow - addressed in versions 3.26.2, 4.1.2
watsonx Code Assistant On Prem - update to 5.3.1
python311-marshmallow - update to 3.20.2-150400.9.10.1
python-marshmallow - update to 3.26.2-1
python-marshmallow-help - update to 3.26.2-1
python3-marshmallow - update to 3.26.2-1

External References

Related Security Bulletins