Commit ee2c59e
NumberConverter: reject scientific notation
BigDecimal support scientific notation, which allow expressing
extremly large numbers with just a few bytes of input.
This could be exploited to DOS a service if somehow user input is
passed to number converter.
[CVE-2026-33176]
[GHSA-2j26-frm8-cmj9]1 parent d7da4ef commit ee2c59e
2 files changed
Lines changed: 13 additions & 1 deletion
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
180 | 180 | | |
181 | 181 | | |
182 | 182 | | |
183 | | - | |
| 183 | + | |
184 | 184 | | |
185 | 185 | | |
186 | 186 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
456 | 456 | | |
457 | 457 | | |
458 | 458 | | |
| 459 | + | |
| 460 | + | |
| 461 | + | |
| 462 | + | |
| 463 | + | |
| 464 | + | |
| 465 | + | |
| 466 | + | |
| 467 | + | |
| 468 | + | |
| 469 | + | |
| 470 | + | |
459 | 471 | | |
460 | 472 | | |
461 | 473 | | |
0 commit comments