CVE-2018-18854

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
31/10/2018
Last modified:
12/12/2018

Description

Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of many JSON object fields (with keys that have the same hash code).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lightbend:spray-json:*:*:*:*:*:*:*:* 1.3.4 (including)


References to Advisories, Solutions, and Tools