- Reported
-
- Issued
-
- Package
-
noyalib
(crates.io)
- Type
-
Vulnerability
- Categories
-
- Keywords
-
#yaml
#resource-exhaustion
#budget
- Aliases
-
- References
-
- Patched
-
- Affected Functions
- Version
noyalib::from_reader
-
noyalib::from_reader_with_config
-
noyalib::from_slice
-
noyalib::from_slice_with_config
-
noyalib::from_str
-
noyalib::from_str_with_config
-
Description
ParserConfig::max_events, max_nodes, max_total_scalar_bytes,
max_merge_keys, alias_anchor_ratio and the alias jump factor were
enforced only by the two Value loaders. A typed target with a
default-shaped configuration is served by the streaming deserializer,
which never read those fields, so tightening any of them had no effect
on from_str::<T> for a struct target. The default document-length,
depth and alias-count caps were enforced on every path, so no input was
unbounded; the gap affects callers who tightened the other budgets for
hostile input.
Version 0.0.53 charges every budget on the streaming path as well and
adds cross-path parity tests.
Users who cannot upgrade can deserialize into noyalib::Value first and
convert with from_value, or rely on max_document_length and
max_depth, which were always applied on every path.
Advisory available under CC-BY-4.0
license.
Source: https://github.com/sebastienrousseau/noyalib/pull/470