Search CVE reports


Toggle filters

1 – 2 of 2 results


CVE-2025-68480

Medium priority

Some fixes available 4 of 6

Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2, Schema.load(data, many=True) is vulnerable to...

1 affected package

python-marshmallow

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-marshmallow Fixed Fixed Fixed Fixed Not affected
Show less packages

CVE-2018-17175

Low priority

Some fixes available 1 of 2

In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema "only" option treats an empty list as implying no "only" option, which allows a request that was intended to expose no fields to instead expose...

1 affected package

python-marshmallow

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-marshmallow Not affected Not affected Not affected Not affected Fixed
Show less packages