CVE-2025-68131

EUVD-2025-205866
cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Starting in version 3.0.0 and prior to version 5.8.0, whhen a CBORDecoder instance is reused across multiple decode operations, values marked with the shareable tag (28) persist in memory and can be accessed by subsequent CBOR messages using the sharedref tag (29). This allows an attacker-controlled message to read data from previously decoded messages if the decoder is reused across trust boundaries. Version 5.8.0 patches the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 36.84%
Affected Products (NVD)
VendorProductVersion
agronholmcbor2
3.0.0 ≤
𝑥
< 5.8.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cbor2
bookworm
unimportant
bullseye
unimportant
forky
6.1.2-2
fixed
sid
6.1.2-2
fixed
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cbor2
jammy
needs-triage
noble
needs-triage
plucky
ignored
questing
ignored
resolute
needs-triage