CVE-2025-0649

Severity CVSS v4.0:
HIGH
Type:
CWE-121 Stack-based Buffer Overflow
Publication date:
06/05/2025
Last modified:
31/07/2025

Description

Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:tensorflow_serving:*:*:*:*:*:*:*:* 2.18.0 (including)