Lucene search

K
githubGitHub Advisory DatabaseGHSA-WW3V-6XJF-JV28
HistoryJun 28, 2022 - 11:23 p.m.

Uncontrolled Resource Consumption in Spray JSON

2022-06-2823:23:20
CWE-400
GitHub Advisory Database
github.com
5
resource consumption
spray json
stackoverflowexceptions
parsers
parsing state

Recursive decent parsers are susceptible too StackOverflowExceptions on too deeply nested structures as currently “open” parsing state is kept on the stack.

Affected configurations

Vulners
Node
io.sprayspray-jsonRange<1.3.5
VendorProductVersionCPE
io.sprayspray-json*cpe:2.3:a:io.spray:spray-json:*:*:*:*:*:*:*:*
Related for GHSA-WW3V-6XJF-JV28