Junglewise Threat Intelligence

CVE-2025-68131: agronholm cbor2 information disclosure via decoder reuse

CVE-2025-68131 · Severity: medium · CVSS 4 · Published 2025-12-31

Technologies: Agronholm Cbor2. Vendors: PyPI.

Executive brief

A vulnerability in the cbor2 Python library allows sensitive data to leak between different messages processed by the same decoder. If an application reuses a decoder to process data from multiple users, a malicious user could craft a message that references and retrieves data from a previous user's message. This could lead to the exposure of private information like credentials or tokens.

Technical details

A vulnerability exists in cbor2 where the CBORDecoder (both C and Python implementations) fails to clear the 'shareables' list when reused across multiple decode operations. This list stores values tagged with CBOR tag 28 (shareable). An attacker can send a crafted CBOR message using tag 29 (sharedref) to reference and retrieve values stored in the shareables list from previously decoded messages. This occurs because the decoder's state persists when decode_from_bytes() is called or when the file pointer is updated. The issue is resolved in version 5.8.0 by implementing flags to reset shared state between top-level decode/encode calls.

Affected products

  • agronholm cbor2 >= 3.0.0, < 5.8.0

Timeline

  • 2025-12-30: disclosed
  • 2025-12-31: advisory: GHSA-wcj4-jw5j-44wh published
  • 2025-12-31: patched: Version 5.8.0 released

References

Related threats