Skip to content

Evaluate: Don’t recurse on untrusted input #514

@blackgnezdo

Description

@blackgnezdo

Unless we got lucky, we are likely affected by the same problem that Java and Python fixed:
https://blog.trailofbits.com/2025/02/21/dont-recurse-on-untrusted-input/

CVE-2024-7254 High CVSS4.0 Score 8.7 (NOTE: there may be a delay in publication)

Somebody could start by adding a test with the known malicious input, e.g. like shown in protocolbuffers/protobuf@a037f28

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions