CVE-2025-67221: Ijl Orjson

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

The orjson.dumps function in orjson thru 3.11.4 does not limit recursion for deeply nested JSON documents.

Affected products

  • Ijl Orjson: up to and including 3.11.4

Published 2026-01-22. Last modified 2026-06-17.