Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Alert Feeds
  • JSON Deserialiser Unconstrained Resource Consumption Quick Overview  – Full Disclosure
AttackFeed by Joe Wagner | JSON Deserialiser Unconstrained Resource Consumption Quick Overview  - Full Disclosure

JSON Deserialiser Unconstrained Resource Consumption Quick Overview  – Full Disclosure

Posted on March 12, 2026 By Joe-W
Alert Feeds

 

Posted by Daniel Owens via Fulldisclosure on Mar 12

As previously mentioned, via “Struts2 and Related Framework Array/Collection DoS” (26 October 2025), hundreds of
JavaScript object notation (JSON) libraries are vulnerable to unconstrained resource consumption through large JSON
arrays, which, when deserialised, create arbitrarily large collections/arrays/data structures. This work looks
specifically at the Apache Struts2 JSON Plugin, using it as an example for why this…
 – Read More  – Full Disclosure 

Post navigation

❮ Previous Post: Stryker attack highlights nebulous nature of Iranian cyber activity amid joint U.S.-Israel conflict  – CyberScoop
Next Post: Defense in depth — the Microsoft way (part 96): yet another SAFER (SRPv1) and AppLocker (SRPv2) loophole  – Full Disclosure ❯

You may also like

AttackFeed by Joe Wagner | SEC Consult SA-20260212-0 :: Multiple Vulnerabilities in various Solax Power Pocket WiFi models  - Full Disclosure
Alert Feeds
SEC Consult SA-20260212-0 :: Multiple Vulnerabilities in various Solax Power Pocket WiFi models  – Full Disclosure
February 16, 2026
AttackFeed by Joe Wagner | APPLE-SA-02-11-2026-2 iOS 18.7.5 and iPadOS 18.7.5  - Full Disclosure
Alert Feeds
APPLE-SA-02-11-2026-2 iOS 18.7.5 and iPadOS 18.7.5  – Full Disclosure
February 16, 2026
AttackFeed by Joe Wagner | Re: SEC Consult SA-20260427-0 :: Missing TLS Certificate Validation leading to RCE in DeskTime Time Tracking App  - Full Disclosure
Alert Feeds
Re: SEC Consult SA-20260427-0 :: Missing TLS Certificate Validation leading to RCE in DeskTime Time Tracking App  – Full Disclosure
April 29, 2026
AttackFeed by Joe Wagner | SEC Consult SA-20260218-0 :: Multiple Critical Vulnerabilities in NesterSoft WorkTime (on-prem/cloud)  - Full Disclosure
Alert Feeds
SEC Consult SA-20260218-0 :: Multiple Critical Vulnerabilities in NesterSoft WorkTime (on-prem/cloud)  – Full Disclosure
February 22, 2026
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.