Early Access — Mondoo Vulnerability Intelligence is currently in preview.
Mondoo Vulnerability Intelligence
Search vulnerabilities and malicious packages across npm, PyPI, Go, GitHub Actions, VS Code, and more.
Search vulnerabilities and malicious packages across npm, PyPI, Go, GitHub Actions, VS Code, and more.
Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2, Schema.load(data, many=True) is vulnerable to denial of service attacks. A moderately sized request can consume a disproportionate amount of CPU time. This issue has been patched in version 3.26.2 and 4.1.2.
3.10.0-13.13.0-13.15.0-13.15.0-1~bpo11+13.18.0-13.20.1-13.20.1-1.13.26.1-0.13.26.1-0.23.18.0-13.20.1-13.20.1-1.13.26.1-0.13.26.1-0.23.26.1-0.23.26.1-0.2Exploitability
AV:NAC:LPR:NUI:NScope
S:UImpact
C:NI:NA:LCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L