Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
631039
AlmaLinux
4656
Alpaquita
8936
Alpine
4052
Android
3261
Azure Linux
12016
BellSoft Hardened Containers
433
Bitnami
7003
Chainguard
5753
CleanStart
791
CRAN
14
crates.io
2241
Debian
54717
Echo
3196
GHC
3
GIT
81487
GitHub Actions
49
Go
6589
Hackage
30
Hex
57
Julia
516
Linux
15361
Mageia
5877
Maven
6327
MinimOS
27422
npm
217526
NuGet
1663
opam
12
openEuler
6511
openSUSE
12588
OSS-Fuzz
3839
Packagist
6087
Pub
11
PyPI
18714
Red Hat
19450
Rocky Linux
2953
Root
12237
RubyGems
1940
SUSE
20565
SwiftURL
50
Ubuntu
52385
VSCode
18
Wolfi
3703
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-428g-f7cq-pgp5
PyPI/marshmallow
Marshmallow has DoS in Schema.load(many)
22 Dec 2025
Fix available
Severity - 5.3 (Medium)
GHSA-9q2p-fj49-vpxj
PyPI/marshmallow
In marshmallow library the schema "only" option treats an empty list as implying no "only" option
10 Oct 2018
Fix available
Severity - 6.9 (Medium)
PYSEC-2018-67
PyPI/marshmallow
See record for full details
18 Sep 2018
Fix available
PyPI - OSV