evtx is vulnerable to Denial of Service (DoS)
44
Medium Risk
BinXML parsing previously allowed attacker-controlled crafted inputs to create extremely deep template/element nesting, potentially causing a stack-overflow crash (DoS). v0.12.2 adds hard recursion/depth caps (e.g., 64 nesting levels and 512 open elements) and threads a depth guard through the BinXML builder/validation so malicious inputs fail with parse errors instead of crashing.
You are affected if you are using a version that falls within the vulnerable range.
evtx is vulnerable to Denial of Service (DoS) in versions 0.10.0 - 0.12.1.
Upgrade the evtx library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant