{"id":"CVE-2024-27454","aliases":["GHSA-pwr2-4v36-6qpr","PYSEC-2024-40"],"url":"https://o3.security/vulnerability/CVE-2024-27454","summary":"orjson does not limit recursion for deeply nested JSON documents","details":"orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents.","published":"2024-02-26T00:00:00Z","modified":"2026-07-22T02:51:16.434238Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AC:L/AV:N/A:H/C:N/I:N/PR:N/S:U/UI:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"orjson","fixedVersion":"3.9.15"}],"fix":{"url":"https://github.com/ijl/orjson/commit/b0e4d2c06ce06c6e63981bf0276e4b7c74e5845e","label":"ijl/orjson@b0e4d2c"},"references":[{"type":"WEB","url":"https://github.com/ijl/orjson/blob/master/CHANGELOG.md#3915"},{"type":"WEB","url":"https://monicz.dev/CVE-2024-27454"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/27xxx/CVE-2024-27454.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-27454"},{"type":"REPORT","url":"https://github.com/ijl/orjson/issues/458"},{"type":"FIX","url":"https://github.com/ijl/orjson/commit/b0e4d2c06ce06c6e63981bf0276e4b7c74e5845e"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-22T02:51:16.434238Z"}}