Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash.
History

Thu, 31 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google tensorflow Serving
Weaknesses CWE-787
CPEs cpe:2.3:a:google:tensorflow_serving:*:*:*:*:*:*:*:*
Vendors & Products Google
Google tensorflow Serving
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00026}

epss

{'score': 0.00028}


Tue, 06 May 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 May 2025 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash.
Title Stack Exhaustion In Tensorflow Serving
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published: 2025-05-06T20:20:02.345Z

Updated: 2025-05-06T20:38:57.927Z

Reserved: 2025-01-22T15:18:16.136Z

Link: CVE-2025-0649

cve-icon Vulnrichment

Updated: 2025-05-06T20:38:51.409Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-06T21:16:17.880

Modified: 2025-07-31T18:12:48.403

Link: CVE-2025-0649

cve-icon Redhat

No data.