{"id":"GHSA-2gg5-7c4v-6xx2","summary":"Duplicate of GHSA-m77f-652q-wwp4","details":"## Duplicate advisory\nThis advisory is a duplicate of [GHSA-m77f-652q-wwp4](https://github.com/advisories/GHSA-m77f-652q-wwp4). This link is maintained to preserve external references.\n\n## Original Description\n\u003cbytes::Bytes as axum_core::extract::FromRequest\u003e::from_request would not, by default, set a limit for the size of the request body. That meant if a malicious peer would send a very large (or infinite) body your server might run out of memory and crash. This also applies to these extractors which used Bytes::from_request internally: axum::extract::Form axum::extract::Json String","modified":"2022-09-19T20:19:08Z","published":"2022-09-15T00:00:19Z","withdrawn":"2022-09-16T20:59:09Z","database_specific":{"nvd_published_at":"2022-09-14T16:15:00Z","cwe_ids":["CWE-770"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-09-16T20:59:09Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-3212"},{"type":"WEB","url":"https://research.jfrog.com/vulnerabilities/axum-core-dos"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2022-0055.html"}],"affected":[{"package":{"name":"axum-core","ecosystem":"crates.io","purl":"pkg:cargo/axum-core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.2.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-2gg5-7c4v-6xx2/GHSA-2gg5-7c4v-6xx2.json"}},{"package":{"name":"axum-core","ecosystem":"crates.io","purl":"pkg:cargo/axum-core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.3.0-rc.1"},{"fixed":"0.3.0-rc.2"}]}],"versions":["0.3.0-rc.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-2gg5-7c4v-6xx2/GHSA-2gg5-7c4v-6xx2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}