Posted by Daniel Owens via Fulldisclosure on Mar 12
As previously mentioned, via “Struts2 and Related Framework Array/Collection DoS” (26 October 2025), hundreds of
JavaScript object notation (JSON) libraries are vulnerable to unconstrained resource consumption through large JSON
arrays, which, when deserialised, create arbitrarily large collections/arrays/data structures. This work looks
specifically at the Apache Struts2 JSON Plugin, using it as an example for why this…
– Read More – Full Disclosure



