Description
In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input.
Remediation
References
https://www.playframework.com/security/vulnerability
https://www.playframework.com/security/vulnerability/CVE-2020-26882-JsonParseDataAmplification
Related Vulnerabilities
CVE-2020-12725 Vulnerability in npm package redash
CVE-2022-42128 Vulnerability in maven package com.liferay:com.liferay.headless.delivery.impl
CVE-2023-20866 Vulnerability in maven package org.springframework.session:spring-session-core
CVE-2011-3375 Vulnerability in maven package org.apache.tomcat:coyote
CVE-2024-36401 Vulnerability in maven package org.geoserver.web:gs-web-app