HIGH7.5
GHSA-qpgv-g792-wh6x
Uncontrolled Resource Consumption in parse_duration
Details
An issue was discovered in the parse_duration crate through 2021-03-18 for Rust. It allows attackers to cause a denial of service (CPU and memory consumption) via a duration string with a large exponent.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/parse_duration
Introduced in:
0No fixed version published yet for parse_duration. Pin to a known-safe version or switch to an alternative.