Skip to content

[GHSA-wgc6-9f6w-h8hx] microlight allows a denial of service#5730

Merged
advisory-database[bot] merged 1 commit intoQix-/advisory-improvement-5730from
Qix--GHSA-wgc6-9f6w-h8hx
Jun 18, 2025
Merged

[GHSA-wgc6-9f6w-h8hx] microlight allows a denial of service#5730
advisory-database[bot] merged 1 commit intoQix-/advisory-improvement-5730from
Qix--GHSA-wgc6-9f6w-h8hx

Conversation

@Qix-
Copy link

@Qix- Qix- commented Jun 18, 2025

This "high severity" advisory shouldn't exist. See #5730 (comment).

Updates

  • Affected products
  • CVSS v4
  • Severity

Comments

From the advisory:

When excessively large content (e.g., 100 million characters) is processed

Tricking anyone into downloading 100MiB of code that is to be processed is of course going to cause DoS. This is a nonsense CVE. Please stop abusing the CVE system for beg bounty / clout-chasing security reports. This has to end.


Screenshots at time of report, just in case context is lost:

image image

Loading
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants