
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67221 is a denial-of-service vulnerability in the orjson.dumps() function of the orjson Python JSON library. The function fails to enforce any recursion limit when serializing deeply nested JSON data structures, allowing an attacker who controls serialized input to trigger a crash. All versions of orjson through 3.11.4 are affected; the patched version is 3.11.6. The vulnerability was published on January 22, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Github Advisory, PoC Repo).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling): the orjson.dumps() serialization routine, implemented in Rust, does not impose a maximum recursion depth when traversing nested Python data structures such as dicts and lists. By contrast, orjson.loads() already enforces a 1024-level recursion limit. An attacker who can supply attacker-controlled data to an application that subsequently calls orjson.dumps() can craft a deeply nested structure (e.g., 100+ levels of nested dicts/lists) that causes unbounded stack recursion, ultimately resulting in a process crash (core dump). No authentication or user interaction is required, and the attack can be delivered remotely over the network if the application accepts external input (Github Advisory, PoC Repo).
Successful exploitation causes a denial of service by crashing the Python process running the vulnerable orjson version, confirmed across Python 3.11–3.14 on both Linux and Windows. There is no impact on confidentiality or integrity — the vulnerability is purely an availability issue. Applications that serialize untrusted or attacker-controlled data structures using orjson are at risk of complete service disruption, and any downstream services depending on the affected application may also be impacted (PoC Repo, Github Advisory).
A public proof-of-concept exploit is available on GitHub, published by researchers from the University of Piraeus and Athens University of Economics and Business (PoC Repo). There is no confirmed evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.04% (low probability of exploitation in the next 30 days) (Github Advisory). No threat actor attribution has been reported.
orjson.dumps().nested = []
for i in range(100):
nested = [{"level": i, "next": nested}]orjson.dumps() — such as an API endpoint, message queue, or file upload.orjson.dumps() call processes the nested structure without a recursion limit, exhausting the stack and causing a core dump / process crash, resulting in denial of service (PoC Repo).Upgrade orjson to version 3.11.6 or later, which introduces a recursion limit for the dumps() function (Github Advisory). IBM has also released patches for affected products including IBM Cloud Pak for Business Automation, IBM Business Automation Workflow, IBM Engineering AI Hub, IBM QRadar Suite Software, and IBM Observability with Instana (OnPrem) (IBM CP4BA Advisory, IBM BAW Advisory). As a temporary workaround for applications that cannot be immediately updated, implement input validation to reject or truncate excessively nested JSON structures before they are passed to orjson.dumps(), and apply resource limits (e.g., process memory/stack limits) to reduce crash impact.
The vulnerability was discovered and disclosed by academic researchers Constantinos Patsakis (University of Piraeus), Evgenios Gkritsis, and George Stergiopoulos (Athens University of Economics and Business), who published a PoC on GitHub (PoC Repo). The GitHub Advisory Database rated the issue as High severity and credited analysts jrafkind-ai and bluestealth for review (Github Advisory). The vulnerability received coverage on security news aggregators and Mastodon shortly after disclosure, and openSUSE issued a security announcement addressing the issue in its distribution packages.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."