-
Notifications
You must be signed in to change notification settings - Fork 307
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Warning about DoS attacks at parsing CUE #158
Comments
Original reply by @rogpeppe in cuelang/cue#158 (comment) Yes, it's definitely vulnerable to that kind of expansion attack. |
Original reply by @rogpeppe in cuelang/cue#158 (comment) Note that this isn't an issue when parsing CUE, only when exporting values from it. |
Original reply by @myitcv in cuelang/cue#158 (comment) Per
e.g.
The said, I think these docs could be better surfaced because I missed this until it was pointed out by @mpvl! |
* usecases: fix various typos
Originally opened by @tredoe in cuelang/cue#158
Does CUE could be vulnerable to a DoS attack like "Billion Laughs" one discovered recently at go-yaml?
kubernetes/kubernetes#83253
The text was updated successfully, but these errors were encountered: