PT-2022-7465 · Haskell+2 · Aeson+2
Published
2022-10-10
·
Updated
2025-11-14
·
CVE-2022-3433
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
aeson (affected versions not specified)
Description
The aeson library is not safe for consuming untrusted JSON input. A remote user could exploit this issue to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service. This technique has been used in real-world attacks against various languages, libraries, and frameworks. The issue results in CPU consumption, leading to a denial of service.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Red Os
Aeson