Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash.
We have discovered 59 live websites that are affected by CVE-2025-0649.
| Product | |
| Category | JavaScript Libraries |
| Vulnerable Domains | 59 live websites (38% of tensorflow install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 9 versions ( 64% of all versions) |
| 42 websites | |
| 4 websites | |
| 2 websites | |
| 2 websites | |
| 2 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites |
| .com | 27 websites |
| .io | 2 websites |
| .net | 2 websites |
| .org | 2 websites |
| .at | 1 websites |
| .ch | 1 websites |
| .com.br | 1 websites |
| .de | 1 websites |
| .dk | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ************.com | ***,*** | ||
| *******.************.de | ***,*** | ||
| ******.me | *,***,*** | ||
| ***********.com | *,***,*** | ||
| ************.com | *,***,*** | ||
| ***********.com | *,***,*** | ||
| *******.**.kr | *,***,*** | ||
| **********.com | *,***,*** | ||
| ******.com | *,***,*** | ||
| *********.******.**********.org | *,***,*** |
FAQ