Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add examples of deserialization issues #681

Merged
merged 1 commit into from
Dec 16, 2023
Merged

Conversation

JackTreble
Copy link
Contributor

@JackTreble JackTreble commented Dec 15, 2023

Encountered (real_world_example whole working on a project.

After writing a fix locally and adding tests I uncovered multiple other instances of array deserialization issues when inside a custom type.

may be related to #504

These seem like the start of a deserialization vulnerability, adding a null into lists is very unusual?

@tminglei tminglei merged commit 31b16e0 into tminglei:master Dec 16, 2023
0 of 16 checks passed
@tminglei
Copy link
Owner

Merged. Thanks! 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants