CVE Explorer
CVE-2025-68131
cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Starting in version 3.0.0 and prior to version 5.8.0, whhen a CBORDecoder instance is reused across multiple decode operations, values marked with the shareable tag (28) persist in memory and can be accessed by subsequent CBOR messages using the sharedref tag (29). This allows an attacker-controlled message to read data from previously decoded messages if the decoder is reused across tr
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"cbor2","vendor":"agronholm","versions":[{"status":"affected","version":">= 3.0.0, < 5.8.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:eea8975045e262d1377ee9749a52995a68a79ea20cad17c8531eaad03b891382 · sha256:0bac73e39254bbf1… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.5,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:eea8975045e262d1377ee9749a52995a68a79ea20cad17c8531eaad03b891382 · sha256:0bac73e39254bbf1… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-212","description":"CWE-212: Improper Removal of Sensitive Information Before Storage or Transfer","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:eea8975045e262d1377ee9749a52995a68a79ea20cad17c8531eaad03b891382 · sha256:0bac73e39254bbf1… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/agronholm/cbor2/pull/268","tags":["x_refsource_MISC"],"url":"https://github.com/agronholm/cbor2/pull/268"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:eea8975045e262d1377ee9749a52995a68a79ea20cad17c8531eaad03b891382 · sha256:0bac73e39254bbf1… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://github.com/agronholm/cbor2/security/advisories/GHSA-wcj4-jw5j-44wh"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:eea8975045e262d1377ee9749a52995a68a79ea20cad17c8531eaad03b891382 · sha256:0bac73e39254bbf1… · /containers/adp/0/references/0
{"name":"https://github.com/agronholm/cbor2/security/advisories/GHSA-wcj4-jw5j-44wh","tags":["x_refsource_CONFIRM"],"url":"https://github.com/agronholm/cbor2/security/advisories/GHSA-wcj4-jw5j-44wh"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:eea8975045e262d1377ee9749a52995a68a79ea20cad17c8531eaad03b891382 · sha256:0bac73e39254bbf1… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.