The aeson library is not safe to use to consume untrusted...
Moderate severity
Unreviewed
Published
Oct 11, 2022
to the GitHub Advisory Database
•
Updated Jul 21, 2023
Description
Published by the National Vulnerability Database
Oct 10, 2022
Published to the GitHub Advisory Database
Oct 11, 2022
Last updated
Jul 21, 2023
The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.
References