CVE-2025-67221: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-67221 is a denial-of-service vulnerability in the orjson.dumps() function of the orjson Python JSON library. The function fails to enforce any recursion limit when serializing deeply nested JSON data structures, allowing an attacker who controls serialized input to trigger a crash. All versions of orjson through 3.11.4 are affected; the patched version is 3.11.6. The vulnerability was published on January 22, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Github Advisory, PoC Repo).

Technical details

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling): the orjson.dumps() serialization routine, implemented in Rust, does not impose a maximum recursion depth when traversing nested Python data structures such as dicts and lists. By contrast, orjson.loads() already enforces a 1024-level recursion limit. An attacker who can supply attacker-controlled data to an application that subsequently calls orjson.dumps() can craft a deeply nested structure (e.g., 100+ levels of nested dicts/lists) that causes unbounded stack recursion, ultimately resulting in a process crash (core dump). No authentication or user interaction is required, and the attack can be delivered remotely over the network if the application accepts external input (Github Advisory, PoC Repo).

Impact

Successful exploitation causes a denial of service by crashing the Python process running the vulnerable orjson version, confirmed across Python 3.11–3.14 on both Linux and Windows. There is no impact on confidentiality or integrity — the vulnerability is purely an availability issue. Applications that serialize untrusted or attacker-controlled data structures using orjson are at risk of complete service disruption, and any downstream services depending on the affected application may also be impacted (PoC Repo, Github Advisory).

Exploitability

A public proof-of-concept exploit is available on GitHub, published by researchers from the University of Piraeus and Athens University of Economics and Business (PoC Repo). There is no confirmed evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.04% (low probability of exploitation in the next 30 days) (Github Advisory). No threat actor attribution has been reported.

Exploitation steps

  1. Identify target: Locate a network-accessible application that accepts external JSON or structured data input and uses orjson ≤ 3.11.4 to serialize that data via orjson.dumps().
  2. Craft malicious payload: Construct a deeply nested Python-compatible data structure. For example, build 100+ levels of nested dicts/lists:
nested = []
for i in range(100):
    nested = [{"level": i, "next": nested}]
  1. Submit payload: Send the deeply nested structure to the target application through any input vector that results in the data being passed to orjson.dumps() — such as an API endpoint, message queue, or file upload.
  2. Trigger crash: The orjson.dumps() call processes the nested structure without a recursion limit, exhausting the stack and causing a core dump / process crash, resulting in denial of service (PoC Repo).

Indicators of compromise

  • Logs: Unexpected application crashes or Python process terminations (core dumps) coinciding with receipt of deeply nested JSON or structured data inputs; error logs showing segmentation faults or stack overflow signals from the orjson library.
  • Process: Sudden termination of Python worker processes without a Python-level exception traceback; repeated process restarts by a supervisor (e.g., systemd, gunicorn, uWSGI) in a short time window.
  • Network: Unusual inbound requests containing deeply nested JSON payloads (e.g., JSON objects with 50+ levels of nesting) to API endpoints that serialize user-supplied data.

Mitigation and workarounds

Upgrade orjson to version 3.11.6 or later, which introduces a recursion limit for the dumps() function (Github Advisory). IBM has also released patches for affected products including IBM Cloud Pak for Business Automation, IBM Business Automation Workflow, IBM Engineering AI Hub, IBM QRadar Suite Software, and IBM Observability with Instana (OnPrem) (IBM CP4BA Advisory, IBM BAW Advisory). As a temporary workaround for applications that cannot be immediately updated, implement input validation to reject or truncate excessively nested JSON structures before they are passed to orjson.dumps(), and apply resource limits (e.g., process memory/stack limits) to reduce crash impact.

Community reactions

The vulnerability was discovered and disclosed by academic researchers Constantinos Patsakis (University of Piraeus), Evgenios Gkritsis, and George Stergiopoulos (Athens University of Economics and Business), who published a PoC on GitHub (PoC Repo). The GitHub Advisory Database rated the issue as High severity and credited analysts jrafkind-ai and bluestealth for review (Github Advisory). The vulnerability received coverage on security news aggregators and Mastodon shortly after disclosure, and openSUSE issued a security announcement addressing the issue in its distribution packages.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management