Description
hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerability allows attackers to cause a Denial of Service (DoS) via manipulation of the first two parameters.
Remediation
References
https://github.com/dromara/hutool/issues/3421
Related Vulnerabilities
CVE-2019-10768 Vulnerability in npm package angular
CVE-2022-29078 Vulnerability in maven package org.webjars.npm:ejs
CVE-2021-21290 Vulnerability in maven package io.netty:netty-codec-http
CVE-2019-9153 Vulnerability in maven package org.webjars.npm:openpgp
CVE-2020-8124 Vulnerability in maven package org.webjars.bowergithub.unshiftio:url-parse