Skip to content

Question regarding the security fix in 2.6.1 #236

Closed Answered by twiss
mdosch asked this question in Q&A
Discussion options

You must be logged in to vote

Hey 👋 It was there for a while, including in 2.5.x. However, note that the impact of the issue was "merely" that parsing untrusted input could cause a panic (which is of course still bad) - this was marked as a security issue because of the potential for denial of service attacks, there were no other security implications beyond that.

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Answer selected by twiss
Comment options

You must be logged in to vote
1 reply
@twiss
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #235 on April 17, 2023 13:41.