Skip to content

Conversation

@htanwar-atlassian
Copy link

Added checks for xml depth, field count, and field size when deserializing. The limits are configurable by the user.
Adding these limits helps in reducing DoS attacks and having stackoverflow exceptions.

The code for adding getLevel is taken from
dfa1d35#diff-eb24140ebbc07aeaa89319c00c32d44fe0f7ee38d8e769039935c60fa5351a5a

@joehni joehni force-pushed the v-1.4.x branch 2 times, most recently from a7492af to c2b9016 Compare September 10, 2025 19:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant