orjson vulnerabilities
CVEs whose affected-version data names the orjson package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-67221HighPoCorjson does not limit recursion for deeply nested JSON documents
orjson does not limit recursion for deeply nested JSON documents
▾ Midnightorjson · orjsonEPSS 0.64%via OSV
CVE-2024-27454High· 7.5orjson does not limit recursion for deeply nested JSON documents
orjson does not limit recursion for deeply nested JSON documents
▾ Twilightorjson · orjsonEPSS 1.2%via OSV