Description
hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerability allows attackers to cause a Denial of Service (DoS) via manipulation of the first two parameters.
Remediation
References
https://github.com/dromara/hutool/issues/3421
Related Vulnerabilities
CVE-2020-15232 Vulnerability in maven package org.mapfish.print:print-lib
CVE-2022-31175 Vulnerability in npm package @ckeditor/ckeditor5-html-support
CVE-2021-29262 Vulnerability in maven package org.apache.solr:solr-core
CVE-2023-34238 Vulnerability in npm package gatsby-transformer-remark
CVE-2022-25646 Vulnerability in npm package x-data-spreadsheet