GDAL is vulnerable to Denial of Service (DoS)
85
High Risk
Affected versions of this package are vulnerable to Denial of Service (DoS) in the GMLASReader class due to insufficient restrictions on XML entity expansion. An attacker can exploit this by providing specially crafted XML files with recursive entity definitions, leading to excessive memory and CPU consumption, ultimately causing the application to become unresponsive.
You are affected if you are using a version that falls within the vulnerable range.
GDAL is vulnerable to Denial of Service (DoS) in versions 2.2.0 - 3.9.2.
Upgrade the GDAL library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant