First published: Tue May 06 2025(Updated: )
Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
TensorFlow Serving | <=2.18.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0649 is considered a high severity vulnerability due to its potential to cause server crashes.
To fix CVE-2025-0649, upgrade Google TensorFlow Serving to version 2.19.0 or later.
CVE-2025-0649 is caused by incorrect JSON input stringification that leads to potentially unbounded recursion.
CVE-2025-0649 affects Google TensorFlow Serving versions up to and including 2.18.0.
If CVE-2025-0649 is not addressed, it could lead to server crashes impacting service availability.