{"id":"CVE-2022-25024","aliases":["GHSA-8rj5-2857-877j","PYSEC-2023-149"],"url":"https://o3.security/vulnerability/CVE-2022-25024","summary":"json2xml Uncaught Exception vulnerability","details":"The json2xml package through 3.12.0 for Python allows an error in typecode decoding enabling a remote attack that can lead to an exception, causing a denial of service.","published":"2023-08-22T00:00:00Z","modified":"2026-08-12T03:51:49.310472478Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"json2xml","fixedVersion":"3.14.0"}],"fix":{"url":"https://github.com/vinitkumar/json2xml/pull/107","label":"vinitkumar/json2xml#107"},"references":[{"type":"WEB","url":"https://github.com/vinitkumar/json2xml/pull/107/files"},{"type":"WEB","url":"https://packaging.python.org/en/latest/guides/analyzing-pypi-package-downloads/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/25xxx/CVE-2022-25024.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-25024"},{"type":"REPORT","url":"https://github.com/vinitkumar/json2xml/issues/106"},{"type":"FIX","url":"https://github.com/vinitkumar/json2xml/pull/107"},{"type":"WEB","url":"https://github.com/vinitkumar/json2xml/commit/a9cd75b61329801b47a8fba7473bce6c85a38b9b"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/json2xml/PYSEC-2023-149.yaml"},{"type":"PACKAGE","url":"https://github.com/vinitkumar/json2xml"},{"type":"WEB","url":"https://packaging.python.org/en/latest/guides/analyzing-pypi-package-downloads"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:49.310472478Z"}}