Description
Those using jackson-dataformats-text to parse TOML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
References (3)
Core 3
Core References
Issue Tracking, Patch, Third Party Advisory
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50083
Scores
CVSS v3
5.8
EPSS
0.0006
EPSS Percentile
19.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-20
CWE-787
Status
published
Products (2)
com.fasterxml.jackson.dataformat/jackson-dataformat-toml
0 - 2.15.0Maven
fasterxml/jackson-dataformats-text
< 2.15.0
Published
Aug 08, 2023
Tracked Since
Feb 18, 2026