CVE-2025-0649: Google Tensorflow Serving
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash.
Affected products
- Google Tensorflow Serving: up to and including 2.18.0
Published 2025-05-06. Last modified 2026-06-17.