jsonparser before 1.1.1 allows attackers to cause a denial of service via a GET call.
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-35381
- https://github.com/buger/jsonparser/issues/219
- https://github.com/buger/jsonparser/pull/221
- https://github.com/buger/jsonparser/commit/df3ea76ece10095374fd1c9a22a4fb85a44efc42
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27EA7OGCELV7QFAGVIHODHWKMKGFVIUZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LJO5N7YTDEUSTKYTNA372CE6VHCZJWUG/
- https://github.com/advisories/GHSA-8vrw-m3j9-j27c