CVE-2025-67221
The orjson.dumps function in orjson thru 3.11.4 does not limit recursion for deeply nested JSON documents.
- Affected products
- Orjson
- Ijl Orjson
- ≤ 3.11.4
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.6% (45th percentile)
- Weakness
- CWE-770
- NVD status
- Analyzed
- Published
- 2026-01-22
CVE-2025-67221 at NVD
1 known exploit for CVE-2025-67221
Proof-of-concept code and exploit modules indexed by Sploitus