Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of many JSON object fields (with keys that have the same hash code).
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| io.spray:spray-json_2.12(Maven) | 0 | 1.3.5 | N/A |
| io.spray:spray-json_2.11(Maven) | 0 | 1.3.5 | N/A |
| io.spray:spray-json_2.10(Maven) | 0 | 1.3.5 | N/A |
CVSS Metrics