CVE-2024-27454: Ijl Orjson

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents.

Affected products

  • Ijl Orjson: before 3.9.15 (fixed in 3.9.15)

Published 2024-02-26. Last modified 2026-06-17.