← All CVEs

CVE-2022-40152

medium · 6.5

Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

6.5
CVSS
19.7%
EPSS (exploit prob.)
97th
EPSS percentile
2022-09-16
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-121CWE-787

Affected products

VendorProductAffected versions
xstreamxstream< 1.4.20
fasterxmlwoodstox< 5.4.0
fasterxmlwoodstox>= 6.0.0, < 6.4.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-40152