-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from unlimited recursion in DTD parsing. The GitHub pull request #159 and issue #160 explicitly show the fix involved adding depth limiting to DTD processing in FullDTDReader. The CVE description specifies the attack requires DTD functionality, and the patch added recursion limits in this component. The FullDTDReader class is responsible for DTD entity resolution where the uncontrolled recursion occurred prior to depth limit checks being implemented.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.fasterxml.woodstox:woodstox-core | maven | >= 6.0.0, < 6.4.0 | 6.4.0 |
| com.fasterxml.woodstox:woodstox-core | maven | < 5.4.0 | 5.4.0 |
Ongoing coverage of React2Shell