Home » Database

AVID-2026-R1647

Description

Stack Exhaustion In Tensorflow Serving (CVE-2025-0649)

Details

Incorrect JSON input stringification in Google’s Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash.

Reason for inclusion in AVID: CVE-2025-0649 describes a stack exhaustion vulnerability in TensorFlow Serving (AI model serving stack) that can cause a server crash due to unbounded recursion. This is a software vulnerability affecting an AI deployment component used in general-purpose AI systems, and it concerns the software supply chain (dependencies/serving stack). The report provides CVE details and a commit reference as evidence.

References

Affected or Relevant Artifacts

  • Developer: Google
  • Deployer: Google
  • Artifact Details:
TypeName
SystemTensorflow

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CWE

IDDescription
CWE-121CWE-121

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2025-05-06
  • Version: 0.3.3
  • AVID Entry