DEBIAN-CVE-2025-0649

Source
https://security-tracker.debian.org/tracker/CVE-2025-0649
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-0649.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2025-0649
Upstream
Withdrawn
2025-11-04T14:19:38.131025Z
Published
2025-05-06T21:16:17Z
Modified
2025-11-04T14:19:38.131025Z
Summary
[none]
Details

Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash.

References

Affected packages

Debian:14 / tensorflow

Package

Name
tensorflow
Purl
pkg:deb/debian/tensorflow?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.10.1+dfsg-A1
1.10.1+dfsg-A2
2.*
2.3.1-1
2.14.1+dfsg-1
2.14.1+dfsg-2
2.14.1+dfsg-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-0649.json"