๐Ÿ” CVE Alert

CVE-2022-3433

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.

CWE CWE-328
Vendor n/a
Product aeson
Published Oct 10, 2022
Last Updated Aug 3, 2024
Stay Ahead of the Next One

Get instant alerts for n/a aeson

Be the first to know when new unknown vulnerabilities affecting n/a aeson are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / aeson
Fixed in 2.0.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
cs-syd.eu: https://cs-syd.eu/posts/2021-09-11-json-vulnerability