Fiche vulnérabilité
CVE-2025-0649 : faille élevée google tensorflow serving (CVSS 7.5)
Description
Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 6 mai 2025
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- google tensorflow serving