Description
Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of a field composed of many decimal digits.
Remediation
References
https://github.com/spray/spray-json/issues/278
Related Vulnerabilities
CVE-2020-25649 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2017-16085 Vulnerability in npm package tinyserver2
CVE-2021-21479 Vulnerability in maven package com.sap.scimono:scimono-server
CVE-2022-34870 Vulnerability in maven package org.apache.geode:geode-pulse
CVE-2023-35110 Vulnerability in maven package de.grobmeier.json:jjson