PT-2020-16529 · Lightbend · Play Framework

Lucash-Dev

·

Published

2020-11-06

·

Updated

2022-02-10

·

CVE-2020-26883

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Play Framework versions 2.6.0 through 2.8.2
Description The issue is caused by unbounded recursion during parsing of crafted JSON documents, leading to stack consumption.
Recommendations For Play Framework versions 2.6.0 through 2.8.2, update to a version that contains a fix for this issue to prevent stack consumption due to unbounded recursion during JSON parsing.

Fix

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26883
GHSA-P8P6-RCP6-4MRM

Affected Products

Play Framework