MEDIUM5.3
PYSEC-2026-1605
Marshmallow has DoS in Schema.load(many)
Quick fix
PYSEC-2026-1605 — marshmallow: upgrade to the fixed version with the command below.
pip install --upgrade 'marshmallow>=3.26.2'Details
### Impact
`Schema.load(data, many=True)` is vulnerable to denial of service attacks. A moderately sized request can consume a disproportionate amount of CPU time.
### Patches
4.1.2, 3.26.2
### Workarounds
```py # Fail fast def load_many(schema, data, **kwargs): if not isinstance(data, list): raise ValidationError(['Invalid input type.']) return [schema.load(item, **kwargs) for item in data] ```
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/marshmallow
Introduced in:
3.0.0rc1Fixed in: 3.26.2Fix
pip install --upgrade 'marshmallow>=3.26.2'References
- https://github.com/marshmallow-code/marshmallow/security/advisories/GHSA-428g-f7cq-pgp5[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-68480[ADVISORY]
- https://github.com/marshmallow-code/marshmallow/commit/d24a0c9df061c4daa92f71cf85aca25b83eee508[WEB]
- https://github.com/marshmallow-code/marshmallow[PACKAGE]
- https://pypi.org/project/marshmallow[PACKAGE]
- https://github.com/advisories/GHSA-428g-f7cq-pgp5[ADVISORY]