The Marshmallow Project maintains a focused Python serialization and deserialization library used across web frameworks and data-processing applications. Known vulnerabilities in the project center on its core marshmallow product and reflect the inherent complexity of schema validation and object handling in a widely embedded serialization tool. Current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Marshmallow Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-17175MEDIUM In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema "only" option treats an empty list as implying no "only" option, which allows a request that | Sep 18, 2018 | 5.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Marshmallow Project.
Media articles that mention a CVE ID that affects a product developed by Marshmallow Project — matched by CVE ID, not by vendor name.