Description
Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of a field composed of many decimal digits.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0748 | Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of a field composed of many decimal digits. |
Github GHSA |
GHSA-f94m-mqhr-mc29 | Uncontrolled Resource Consumption in spray-json when parsing decimal digit fields |
References
| Link | Providers |
|---|---|
| https://github.com/spray/spray-json/issues/278 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:23:08.291Z
Reserved: 2018-10-30T00:00:00.000Z
Link: CVE-2018-18853
No data.
Status : Modified
Published: 2018-10-31T05:29:00.250
Modified: 2024-11-21T03:56:45.017
Link: CVE-2018-18853
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA