VDB
Sign up
—

RUSTSEC-2024-0012

Stack overflow during recursive JSON parsing

Details

When parsing untrusted, deeply nested JSON, the stack may overflow, possibly enabling a Denial of Service attack. This was fixed by adding a check for recursion depth.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/serde-json-wasm
Introduced in: 0.0.0-0Fixed in: 0.5.2

Upgrade serde-json-wasm to 0.5.2 or newer (ecosystem crates.io).

References