Lucene search

K
osvGoogleOSV:GHSA-XMC8-26Q4-QJHX
HistoryDec 09, 2021 - 7:17 p.m.

Denial of Service (DoS) in Jackson Dataformat CBOR

2021-12-0919:17:21
Google
osv.dev
18

0.001 Low

EPSS

Percentile

44.4%

This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 2.8.0-rc1 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.