The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.google.code.gson:gson(Maven) | 0 | 2.8.9 | N/A |
CVSS Metrics