Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pjvp-v6mq-82xv

Опубликовано: 24 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, which fixes this issue by imposing a default maximum size on data read from remote policy references.

Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, which fixes this issue by imposing a default maximum size on data read from remote policy references.

EPSS

Процентиль: 39%
0.00478
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
nvd
14 дней назад

Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, which fixes this issue by imposing a default maximum size on data read from remote policy references.

EPSS

Процентиль: 39%
0.00478
Низкий

7.5 High

CVSS3

Дефекты

CWE-400