PeterO.Cbor
A C# implementation of Concise Binary Object Representation (CBOR), a general-purpose binary data format defined in RFC 8949.
Activity
- Latest release
- 2y ago
- Total releases
- 24
- Cadence
- ~39 days
- Last 12 months
- 0
Details
- License
- CC0-1.0
- First release
- Jul 30, 2018
| Version | Released | |
|---|---|---|
4.5.5
patch
| ||
5.0.0-alpha2
pre
| ||
5.0.0-alpha1
pre
| ||
4.5.3
patch
| ||
4.5.2
patch
| ||
4.5.1
patch
| ||
4.5.0
minor
1 CVE
CVE-2024-21909
GHSA-6r92-cgxc-r5fg
Jan 21, 2022
Denial of service in CBOR library
High
ImpactDue to this library's use of an inefficient algorithm, it is vulnerable to a denial of service attack when a maliciously crafted input is passed to Affected versions include versions 4.0.0 through 4.5.0. This vulnerability was privately reported to me. PatchesThis issue has been fixed in version 4.5.1. Users should use the latest version of this library. (The latest version is not necessarily 4.5.1. Check the NuGet page to see the latest version's version number.) WorkaroundsAgain, users should use the latest version of this library. In the meantime, note that the inputs affected by this issue are all CBOR maps or contain CBOR maps. An input that decodes to a single CBOR object is not capable of containing a CBOR map if—
Such an input is not affected by this vulnerability and an application can choose to perform this check before passing it to a CBOR decoding mechanism. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.1
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
4.3.0
4.4.0
4.4.1
4.4.2
4.4.4
+ 1 more Show less
4.5.0
Fixed in
4.5.1
References Updated Jul 08, 2026 · Source: OSV.dev | ||
4.4.4
patch
1 CVE
CVE-2024-21909
GHSA-6r92-cgxc-r5fg
Jan 21, 2022
Denial of service in CBOR library
High
ImpactDue to this library's use of an inefficient algorithm, it is vulnerable to a denial of service attack when a maliciously crafted input is passed to Affected versions include versions 4.0.0 through 4.5.0. This vulnerability was privately reported to me. PatchesThis issue has been fixed in version 4.5.1. Users should use the latest version of this library. (The latest version is not necessarily 4.5.1. Check the NuGet page to see the latest version's version number.) WorkaroundsAgain, users should use the latest version of this library. In the meantime, note that the inputs affected by this issue are all CBOR maps or contain CBOR maps. An input that decodes to a single CBOR object is not capable of containing a CBOR map if—
Such an input is not affected by this vulnerability and an application can choose to perform this check before passing it to a CBOR decoding mechanism. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.1
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
4.3.0
4.4.0
4.4.1
4.4.2
4.4.4
+ 1 more Show less
4.5.0
Fixed in
4.5.1
References Updated Jul 08, 2026 · Source: OSV.dev | ||
4.4.2
patch
1 CVE
CVE-2024-21909
GHSA-6r92-cgxc-r5fg
Jan 21, 2022
Denial of service in CBOR library
High
ImpactDue to this library's use of an inefficient algorithm, it is vulnerable to a denial of service attack when a maliciously crafted input is passed to Affected versions include versions 4.0.0 through 4.5.0. This vulnerability was privately reported to me. PatchesThis issue has been fixed in version 4.5.1. Users should use the latest version of this library. (The latest version is not necessarily 4.5.1. Check the NuGet page to see the latest version's version number.) WorkaroundsAgain, users should use the latest version of this library. In the meantime, note that the inputs affected by this issue are all CBOR maps or contain CBOR maps. An input that decodes to a single CBOR object is not capable of containing a CBOR map if—
Such an input is not affected by this vulnerability and an application can choose to perform this check before passing it to a CBOR decoding mechanism. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.1
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
4.3.0
4.4.0
4.4.1
4.4.2
4.4.4
+ 1 more Show less
4.5.0
Fixed in
4.5.1
References Updated Jul 08, 2026 · Source: OSV.dev | ||
4.4.1
patch
1 CVE
CVE-2024-21909
GHSA-6r92-cgxc-r5fg
Jan 21, 2022
Denial of service in CBOR library
High
ImpactDue to this library's use of an inefficient algorithm, it is vulnerable to a denial of service attack when a maliciously crafted input is passed to Affected versions include versions 4.0.0 through 4.5.0. This vulnerability was privately reported to me. PatchesThis issue has been fixed in version 4.5.1. Users should use the latest version of this library. (The latest version is not necessarily 4.5.1. Check the NuGet page to see the latest version's version number.) WorkaroundsAgain, users should use the latest version of this library. In the meantime, note that the inputs affected by this issue are all CBOR maps or contain CBOR maps. An input that decodes to a single CBOR object is not capable of containing a CBOR map if—
Such an input is not affected by this vulnerability and an application can choose to perform this check before passing it to a CBOR decoding mechanism. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.1
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
4.3.0
4.4.0
4.4.1
4.4.2
4.4.4
+ 1 more Show less
4.5.0
Fixed in
4.5.1
References Updated Jul 08, 2026 · Source: OSV.dev | ||
4.4.0
minor
1 CVE
CVE-2024-21909
GHSA-6r92-cgxc-r5fg
Jan 21, 2022
Denial of service in CBOR library
High
ImpactDue to this library's use of an inefficient algorithm, it is vulnerable to a denial of service attack when a maliciously crafted input is passed to Affected versions include versions 4.0.0 through 4.5.0. This vulnerability was privately reported to me. PatchesThis issue has been fixed in version 4.5.1. Users should use the latest version of this library. (The latest version is not necessarily 4.5.1. Check the NuGet page to see the latest version's version number.) WorkaroundsAgain, users should use the latest version of this library. In the meantime, note that the inputs affected by this issue are all CBOR maps or contain CBOR maps. An input that decodes to a single CBOR object is not capable of containing a CBOR map if—
Such an input is not affected by this vulnerability and an application can choose to perform this check before passing it to a CBOR decoding mechanism. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.1
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
4.3.0
4.4.0
4.4.1
4.4.2
4.4.4
+ 1 more Show less
4.5.0
Fixed in
4.5.1
References Updated Jul 08, 2026 · Source: OSV.dev | ||
4.3.0
minor
1 CVE
CVE-2024-21909
GHSA-6r92-cgxc-r5fg
Jan 21, 2022
Denial of service in CBOR library
High
ImpactDue to this library's use of an inefficient algorithm, it is vulnerable to a denial of service attack when a maliciously crafted input is passed to Affected versions include versions 4.0.0 through 4.5.0. This vulnerability was privately reported to me. PatchesThis issue has been fixed in version 4.5.1. Users should use the latest version of this library. (The latest version is not necessarily 4.5.1. Check the NuGet page to see the latest version's version number.) WorkaroundsAgain, users should use the latest version of this library. In the meantime, note that the inputs affected by this issue are all CBOR maps or contain CBOR maps. An input that decodes to a single CBOR object is not capable of containing a CBOR map if—
Such an input is not affected by this vulnerability and an application can choose to perform this check before passing it to a CBOR decoding mechanism. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.1
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
4.3.0
4.4.0
4.4.1
4.4.2
4.4.4
+ 1 more Show less
4.5.0
Fixed in
4.5.1
References Updated Jul 08, 2026 · Source: OSV.dev | ||
4.2.0
minor
1 CVE
CVE-2024-21909
GHSA-6r92-cgxc-r5fg
Jan 21, 2022
Denial of service in CBOR library
High
ImpactDue to this library's use of an inefficient algorithm, it is vulnerable to a denial of service attack when a maliciously crafted input is passed to Affected versions include versions 4.0.0 through 4.5.0. This vulnerability was privately reported to me. PatchesThis issue has been fixed in version 4.5.1. Users should use the latest version of this library. (The latest version is not necessarily 4.5.1. Check the NuGet page to see the latest version's version number.) WorkaroundsAgain, users should use the latest version of this library. In the meantime, note that the inputs affected by this issue are all CBOR maps or contain CBOR maps. An input that decodes to a single CBOR object is not capable of containing a CBOR map if—
Such an input is not affected by this vulnerability and an application can choose to perform this check before passing it to a CBOR decoding mechanism. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.1
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
4.3.0
4.4.0
4.4.1
4.4.2
4.4.4
+ 1 more Show less
4.5.0
Fixed in
4.5.1
References Updated Jul 08, 2026 · Source: OSV.dev | ||
4.1.3
patch
1 CVE
CVE-2024-21909
GHSA-6r92-cgxc-r5fg
Jan 21, 2022
Denial of service in CBOR library
High
ImpactDue to this library's use of an inefficient algorithm, it is vulnerable to a denial of service attack when a maliciously crafted input is passed to Affected versions include versions 4.0.0 through 4.5.0. This vulnerability was privately reported to me. PatchesThis issue has been fixed in version 4.5.1. Users should use the latest version of this library. (The latest version is not necessarily 4.5.1. Check the NuGet page to see the latest version's version number.) WorkaroundsAgain, users should use the latest version of this library. In the meantime, note that the inputs affected by this issue are all CBOR maps or contain CBOR maps. An input that decodes to a single CBOR object is not capable of containing a CBOR map if—
Such an input is not affected by this vulnerability and an application can choose to perform this check before passing it to a CBOR decoding mechanism. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.1
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
4.3.0
4.4.0
4.4.1
4.4.2
4.4.4
+ 1 more Show less
4.5.0
Fixed in
4.5.1
References Updated Jul 08, 2026 · Source: OSV.dev | ||
4.1.2
patch
1 CVE
CVE-2024-21909
GHSA-6r92-cgxc-r5fg
Jan 21, 2022
Denial of service in CBOR library
High
ImpactDue to this library's use of an inefficient algorithm, it is vulnerable to a denial of service attack when a maliciously crafted input is passed to Affected versions include versions 4.0.0 through 4.5.0. This vulnerability was privately reported to me. PatchesThis issue has been fixed in version 4.5.1. Users should use the latest version of this library. (The latest version is not necessarily 4.5.1. Check the NuGet page to see the latest version's version number.) WorkaroundsAgain, users should use the latest version of this library. In the meantime, note that the inputs affected by this issue are all CBOR maps or contain CBOR maps. An input that decodes to a single CBOR object is not capable of containing a CBOR map if—
Such an input is not affected by this vulnerability and an application can choose to perform this check before passing it to a CBOR decoding mechanism. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.1
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
4.3.0
4.4.0
4.4.1
4.4.2
4.4.4
+ 1 more Show less
4.5.0
Fixed in
4.5.1
References Updated Jul 08, 2026 · Source: OSV.dev | ||
4.1.1
patch
1 CVE
CVE-2024-21909
GHSA-6r92-cgxc-r5fg
Jan 21, 2022
Denial of service in CBOR library
High
ImpactDue to this library's use of an inefficient algorithm, it is vulnerable to a denial of service attack when a maliciously crafted input is passed to Affected versions include versions 4.0.0 through 4.5.0. This vulnerability was privately reported to me. PatchesThis issue has been fixed in version 4.5.1. Users should use the latest version of this library. (The latest version is not necessarily 4.5.1. Check the NuGet page to see the latest version's version number.) WorkaroundsAgain, users should use the latest version of this library. In the meantime, note that the inputs affected by this issue are all CBOR maps or contain CBOR maps. An input that decodes to a single CBOR object is not capable of containing a CBOR map if—
Such an input is not affected by this vulnerability and an application can choose to perform this check before passing it to a CBOR decoding mechanism. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.1
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
4.3.0
4.4.0
4.4.1
4.4.2
4.4.4
+ 1 more Show less
4.5.0
Fixed in
4.5.1
References Updated Jul 08, 2026 · Source: OSV.dev | ||
4.1.0
minor
1 CVE
CVE-2024-21909
GHSA-6r92-cgxc-r5fg
Jan 21, 2022
Denial of service in CBOR library
High
ImpactDue to this library's use of an inefficient algorithm, it is vulnerable to a denial of service attack when a maliciously crafted input is passed to Affected versions include versions 4.0.0 through 4.5.0. This vulnerability was privately reported to me. PatchesThis issue has been fixed in version 4.5.1. Users should use the latest version of this library. (The latest version is not necessarily 4.5.1. Check the NuGet page to see the latest version's version number.) WorkaroundsAgain, users should use the latest version of this library. In the meantime, note that the inputs affected by this issue are all CBOR maps or contain CBOR maps. An input that decodes to a single CBOR object is not capable of containing a CBOR map if—
Such an input is not affected by this vulnerability and an application can choose to perform this check before passing it to a CBOR decoding mechanism. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.1
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
4.3.0
4.4.0
4.4.1
4.4.2
4.4.4
+ 1 more Show less
4.5.0
Fixed in
4.5.1
References Updated Jul 08, 2026 · Source: OSV.dev | ||
4.0.0
major
1 CVE
CVE-2024-21909
GHSA-6r92-cgxc-r5fg
Jan 21, 2022
Denial of service in CBOR library
High
ImpactDue to this library's use of an inefficient algorithm, it is vulnerable to a denial of service attack when a maliciously crafted input is passed to Affected versions include versions 4.0.0 through 4.5.0. This vulnerability was privately reported to me. PatchesThis issue has been fixed in version 4.5.1. Users should use the latest version of this library. (The latest version is not necessarily 4.5.1. Check the NuGet page to see the latest version's version number.) WorkaroundsAgain, users should use the latest version of this library. In the meantime, note that the inputs affected by this issue are all CBOR maps or contain CBOR maps. An input that decodes to a single CBOR object is not capable of containing a CBOR map if—
Such an input is not affected by this vulnerability and an application can choose to perform this check before passing it to a CBOR decoding mechanism. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.1
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
4.3.0
4.4.0
4.4.1
4.4.2
4.4.4
+ 1 more Show less
4.5.0
Fixed in
4.5.1
References Updated Jul 08, 2026 · Source: OSV.dev | ||
3.5.2
patch
1 CVE
GHSA-cxw4-9qv9-vx5h
Sep 30, 2019
High severity vulnerability that affects PeterO.Cbor
High
ImpactThe CBOR library supports optional tags that enable CBOR objects to contain references to objects within them. Versions earlier than 4.0 resolved those references automatically. While this by itself doesn't cause much of a security problem, a denial of service can happen if those references are deeply nested and used multiple times (so that the same reference to the same object occurs multiple times), and if the decoded CBOR object is sent to a serialization method such as The impact of this problem on any particular system varies. In general, the risk is higher if the system allows users to send arbitrary CBOR objects without authentication, or exposes a remote endpoint in which arbitrary CBOR objects can be sent without authentication. PatchesThis problem is addressed in version 4.0 by disabling reference resolution by default. Users should use the latest version of this library. WorkaroundsSince version 3.6, an encoding option ( In version 3.6, if the method used
In versions 3.5 and earlier, this issue is present only if the CBOR object is an array or a map. If the application does not expect a decoded CBOR object to be an array or a map, it should check the CBOR object's type before encoding that object, as follows:
Alternatively, for such versions, the application can use
To check whether a byte array representing a CBOR object might exhibit this problem, check whether the array contains the byte 0xd8 followed immediately by either 0x19 or 0x1d. This check catches all affected CBOR objects but may catch some non-affected CBOR objects (notably integers and byte strings). ReferencesSee the Wikipedia article Billion laughs attack and the related issue in Kubernetes. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.21.0
0.22.0
0.23.0
1.0.0
1.1.0
1.2.0
1.3.0
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
+ 25 more Show less
2.4.0
2.4.1
2.4.2
2.5.0
2.5.1
2.5.2
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
3.4.0-alpha1
3.4.0-beta1
3.5.0
3.5.1
3.5.2
3.6.0
4.0.0-alpha1
4.0.0-alpha2
4.0.0-beta1
4.0.0-beta2
Fixed in
4.0.0
References Updated Dec 02, 2024 · Source: OSV.dev | ||
3.5.1
patch
1 CVE
GHSA-cxw4-9qv9-vx5h
Sep 30, 2019
High severity vulnerability that affects PeterO.Cbor
High
ImpactThe CBOR library supports optional tags that enable CBOR objects to contain references to objects within them. Versions earlier than 4.0 resolved those references automatically. While this by itself doesn't cause much of a security problem, a denial of service can happen if those references are deeply nested and used multiple times (so that the same reference to the same object occurs multiple times), and if the decoded CBOR object is sent to a serialization method such as The impact of this problem on any particular system varies. In general, the risk is higher if the system allows users to send arbitrary CBOR objects without authentication, or exposes a remote endpoint in which arbitrary CBOR objects can be sent without authentication. PatchesThis problem is addressed in version 4.0 by disabling reference resolution by default. Users should use the latest version of this library. WorkaroundsSince version 3.6, an encoding option ( In version 3.6, if the method used
In versions 3.5 and earlier, this issue is present only if the CBOR object is an array or a map. If the application does not expect a decoded CBOR object to be an array or a map, it should check the CBOR object's type before encoding that object, as follows:
Alternatively, for such versions, the application can use
To check whether a byte array representing a CBOR object might exhibit this problem, check whether the array contains the byte 0xd8 followed immediately by either 0x19 or 0x1d. This check catches all affected CBOR objects but may catch some non-affected CBOR objects (notably integers and byte strings). ReferencesSee the Wikipedia article Billion laughs attack and the related issue in Kubernetes. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.21.0
0.22.0
0.23.0
1.0.0
1.1.0
1.2.0
1.3.0
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
+ 25 more Show less
2.4.0
2.4.1
2.4.2
2.5.0
2.5.1
2.5.2
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
3.4.0-alpha1
3.4.0-beta1
3.5.0
3.5.1
3.5.2
3.6.0
4.0.0-alpha1
4.0.0-alpha2
4.0.0-beta1
4.0.0-beta2
Fixed in
4.0.0
References Updated Dec 02, 2024 · Source: OSV.dev | ||
3.5.0
minor
1 CVE
GHSA-cxw4-9qv9-vx5h
Sep 30, 2019
High severity vulnerability that affects PeterO.Cbor
High
ImpactThe CBOR library supports optional tags that enable CBOR objects to contain references to objects within them. Versions earlier than 4.0 resolved those references automatically. While this by itself doesn't cause much of a security problem, a denial of service can happen if those references are deeply nested and used multiple times (so that the same reference to the same object occurs multiple times), and if the decoded CBOR object is sent to a serialization method such as The impact of this problem on any particular system varies. In general, the risk is higher if the system allows users to send arbitrary CBOR objects without authentication, or exposes a remote endpoint in which arbitrary CBOR objects can be sent without authentication. PatchesThis problem is addressed in version 4.0 by disabling reference resolution by default. Users should use the latest version of this library. WorkaroundsSince version 3.6, an encoding option ( In version 3.6, if the method used
In versions 3.5 and earlier, this issue is present only if the CBOR object is an array or a map. If the application does not expect a decoded CBOR object to be an array or a map, it should check the CBOR object's type before encoding that object, as follows:
Alternatively, for such versions, the application can use
To check whether a byte array representing a CBOR object might exhibit this problem, check whether the array contains the byte 0xd8 followed immediately by either 0x19 or 0x1d. This check catches all affected CBOR objects but may catch some non-affected CBOR objects (notably integers and byte strings). ReferencesSee the Wikipedia article Billion laughs attack and the related issue in Kubernetes. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.21.0
0.22.0
0.23.0
1.0.0
1.1.0
1.2.0
1.3.0
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
+ 25 more Show less
2.4.0
2.4.1
2.4.2
2.5.0
2.5.1
2.5.2
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
3.4.0-alpha1
3.4.0-beta1
3.5.0
3.5.1
3.5.2
3.6.0
4.0.0-alpha1
4.0.0-alpha2
4.0.0-beta1
4.0.0-beta2
Fixed in
4.0.0
References Updated Dec 02, 2024 · Source: OSV.dev | ||
3.4.0-beta1
pre
1 CVE
GHSA-cxw4-9qv9-vx5h
Sep 30, 2019
High severity vulnerability that affects PeterO.Cbor
High
ImpactThe CBOR library supports optional tags that enable CBOR objects to contain references to objects within them. Versions earlier than 4.0 resolved those references automatically. While this by itself doesn't cause much of a security problem, a denial of service can happen if those references are deeply nested and used multiple times (so that the same reference to the same object occurs multiple times), and if the decoded CBOR object is sent to a serialization method such as The impact of this problem on any particular system varies. In general, the risk is higher if the system allows users to send arbitrary CBOR objects without authentication, or exposes a remote endpoint in which arbitrary CBOR objects can be sent without authentication. PatchesThis problem is addressed in version 4.0 by disabling reference resolution by default. Users should use the latest version of this library. WorkaroundsSince version 3.6, an encoding option ( In version 3.6, if the method used
In versions 3.5 and earlier, this issue is present only if the CBOR object is an array or a map. If the application does not expect a decoded CBOR object to be an array or a map, it should check the CBOR object's type before encoding that object, as follows:
Alternatively, for such versions, the application can use
To check whether a byte array representing a CBOR object might exhibit this problem, check whether the array contains the byte 0xd8 followed immediately by either 0x19 or 0x1d. This check catches all affected CBOR objects but may catch some non-affected CBOR objects (notably integers and byte strings). ReferencesSee the Wikipedia article Billion laughs attack and the related issue in Kubernetes. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.21.0
0.22.0
0.23.0
1.0.0
1.1.0
1.2.0
1.3.0
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
+ 25 more Show less
2.4.0
2.4.1
2.4.2
2.5.0
2.5.1
2.5.2
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
3.4.0-alpha1
3.4.0-beta1
3.5.0
3.5.1
3.5.2
3.6.0
4.0.0-alpha1
4.0.0-alpha2
4.0.0-beta1
4.0.0-beta2
Fixed in
4.0.0
References Updated Dec 02, 2024 · Source: OSV.dev | ||
3.3.0
minor
1 CVE
GHSA-cxw4-9qv9-vx5h
Sep 30, 2019
High severity vulnerability that affects PeterO.Cbor
High
ImpactThe CBOR library supports optional tags that enable CBOR objects to contain references to objects within them. Versions earlier than 4.0 resolved those references automatically. While this by itself doesn't cause much of a security problem, a denial of service can happen if those references are deeply nested and used multiple times (so that the same reference to the same object occurs multiple times), and if the decoded CBOR object is sent to a serialization method such as The impact of this problem on any particular system varies. In general, the risk is higher if the system allows users to send arbitrary CBOR objects without authentication, or exposes a remote endpoint in which arbitrary CBOR objects can be sent without authentication. PatchesThis problem is addressed in version 4.0 by disabling reference resolution by default. Users should use the latest version of this library. WorkaroundsSince version 3.6, an encoding option ( In version 3.6, if the method used
In versions 3.5 and earlier, this issue is present only if the CBOR object is an array or a map. If the application does not expect a decoded CBOR object to be an array or a map, it should check the CBOR object's type before encoding that object, as follows:
Alternatively, for such versions, the application can use
To check whether a byte array representing a CBOR object might exhibit this problem, check whether the array contains the byte 0xd8 followed immediately by either 0x19 or 0x1d. This check catches all affected CBOR objects but may catch some non-affected CBOR objects (notably integers and byte strings). ReferencesSee the Wikipedia article Billion laughs attack and the related issue in Kubernetes. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.21.0
0.22.0
0.23.0
1.0.0
1.1.0
1.2.0
1.3.0
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
+ 25 more Show less
2.4.0
2.4.1
2.4.2
2.5.0
2.5.1
2.5.2
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
3.4.0-alpha1
3.4.0-beta1
3.5.0
3.5.1
3.5.2
3.6.0
4.0.0-alpha1
4.0.0-alpha2
4.0.0-beta1
4.0.0-beta2
Fixed in
4.0.0
References Updated Dec 02, 2024 · Source: OSV.dev | ||
3.2.0
initial
1 CVE
GHSA-cxw4-9qv9-vx5h
Sep 30, 2019
High severity vulnerability that affects PeterO.Cbor
High
ImpactThe CBOR library supports optional tags that enable CBOR objects to contain references to objects within them. Versions earlier than 4.0 resolved those references automatically. While this by itself doesn't cause much of a security problem, a denial of service can happen if those references are deeply nested and used multiple times (so that the same reference to the same object occurs multiple times), and if the decoded CBOR object is sent to a serialization method such as The impact of this problem on any particular system varies. In general, the risk is higher if the system allows users to send arbitrary CBOR objects without authentication, or exposes a remote endpoint in which arbitrary CBOR objects can be sent without authentication. PatchesThis problem is addressed in version 4.0 by disabling reference resolution by default. Users should use the latest version of this library. WorkaroundsSince version 3.6, an encoding option ( In version 3.6, if the method used
In versions 3.5 and earlier, this issue is present only if the CBOR object is an array or a map. If the application does not expect a decoded CBOR object to be an array or a map, it should check the CBOR object's type before encoding that object, as follows:
Alternatively, for such versions, the application can use
To check whether a byte array representing a CBOR object might exhibit this problem, check whether the array contains the byte 0xd8 followed immediately by either 0x19 or 0x1d. This check catches all affected CBOR objects but may catch some non-affected CBOR objects (notably integers and byte strings). ReferencesSee the Wikipedia article Billion laughs attack and the related issue in Kubernetes. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.21.0
0.22.0
0.23.0
1.0.0
1.1.0
1.2.0
1.3.0
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
+ 25 more Show less
2.4.0
2.4.1
2.4.2
2.5.0
2.5.1
2.5.2
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
3.4.0-alpha1
3.4.0-beta1
3.5.0
3.5.1
3.5.2
3.6.0
4.0.0-alpha1
4.0.0-alpha2
4.0.0-beta1
4.0.0-beta2
Fixed in
4.0.0
References Updated Dec 02, 2024 · Source: OSV.dev |