orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-0130 orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents.
Github GHSA Github GHSA GHSA-pwr2-4v36-6qpr orjson does not limit recursion for deeply nested JSON documents
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 18 Sep 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Ijl
Ijl orjson
CPEs cpe:2.3:a:ijl:orjson:*:*:*:*:*:python:*:*
Vendors & Products Ijl
Ijl orjson

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T17:14:21.107Z

Reserved: 2024-02-26T00:00:00

Link: CVE-2024-27454

cve-icon Vulnrichment

Updated: 2024-08-02T00:34:52.395Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-26T16:28:00.530

Modified: 2025-09-18T16:23:58.163

Link: CVE-2024-27454

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.