Vulnerability Report: GO-2023-1269

Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack.

For detailed information about this vulnerability, visit https://github.com/ipld/go-ipld-prime/security/advisories/GHSA-c653-6hhg-9x92.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL