Aeson / text-iso8601 have a vulnerability, let's update bounds
Haskell Community
Aeson / text-iso8601 have a vulnerability, let's update bounds
TLDR: If you depend on aeson, please bump your upper bound to <2.4. For folks who have been confused about this, like me: aeson 2.3.0.0 (2026-05-21) fixes HSEC-2026-0007, a remotely-triggerable memory-exhaustion DoS. It also requires text-iso8601 >= 0.2, fixing the second half of that advisory. The packages still capped at <2.3 are collectively holding the ecosystem to versions with a published denial-of-service advisory. [for 3 months and counting.] Two things that might unstick this: Y...
0 comments
No comments yet.