HSEC-2026-0007

See a problem?
Import Source
https://github.com/haskell/security-advisories/blob/generated/osv-export/2026/HSEC-2026-0007.json
JSON Data
https://api.test.osv.dev/v1/vulns/HSEC-2026-0007
Published
2026-05-22T07:02:58Z
Modified
2026-09-16T23:00:03Z
Summary
Denial of Service and Memory Exhaustion in aeson
Details

Denial of Service and Memory Exhaustion in aeson

A Denial of Service (DoS) and memory exhaustion vulnerability was identified in the aeson package. The vulnerability allows an attacker to exhaust server memory and crash the host process by supplying maliciously crafted JSON payloads.

The vulnerability exists in aeson's withBoundedScientific_ function (located in src/Data/Aeson/Types/FromJSON.hs). The exponent bounds check only rejects large positive exponents (exp10 > 1024) but fails to reject arbitrarily large negative exponents.

When an attacker sends a JSON number with a massive negative exponent (e.g., 1e-999999999), the value bypasses the check and flows into realToFrac, which computes fromRational . toRational. For such a large negative exponent, toRational produces a GMP Integer with approximately 1 billion decimal digits, causing immediate and severe memory exhaustion.

Affected FromJSON instances:

  • Fixed a (including Centi, Pico, Nano, etc.)
  • NominalDiffTime
  • DiffTime

Resolution

The issue was resolved by introducing proper bounds checks:

  • aeson now applies an absolute bounds check to both positive and negative exponents (abs exp10 > 1024).

The fix first shipped in aeson-2.3.0.0, and have been backported to the previous release series as aeson-2.2.5.1.

Users are strongly advised to update to the patched versions:

  • aeson-2.2.5.1 or later

Acknowledgements

The vulnerabilities were reported Nathan Walsh, and patched by Li-yao Xia.

Database specific
{
    "home":  "https://github.com/haskell/security-advisories",
    "osvs":  "https://raw.githubusercontent.com/haskell/security-advisories/refs/heads/generated/osv-export",
    "repository":  "https://github.com/haskell/security-advisories"
}
References

Affected packages

Hackage / aeson

Package

Name
aeson
Purl
pkg:hackage/aeson

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.12.0.0
Fixed
2.2.5.1

Affected versions

1.*
1.0.0.0
1.0.1.0
1.0.2.0
1.0.2.1
1.1.0.0
1.1.1.0
1.1.2.0
1.2.0.0
1.2.1.0
1.2.2.0
1.2.3.0
1.2.4.0
1.3.0.0
1.3.1.0
1.3.1.1
1.4.0.0
1.4.1.0
1.4.2.0
1.4.3.0
1.4.4.0
1.4.5.0
1.4.6.0
1.4.7.0
1.4.7.1
1.5.0.0
1.5.1.0
1.5.2.0
1.5.3.0
1.5.4.0
1.5.4.1
1.5.5.0
1.5.5.1
1.5.6.0
2.*
2.0.0.0
2.0.1.0
2.0.2.0
2.0.3.0
2.1.0.0
2.1.1.0
2.1.2.0
2.1.2.1
2.2.0.0
2.2.1.0
2.2.2.0
2.2.3.0
2.2.4.0
2.2.4.1
2.2.5.0

Database specific

human_link
"https://github.com/haskell/security-advisories/tree/main/advisories/published/2026/HSEC-2026-0007.md"
osv
"https://raw.githubusercontent.com/haskell/security-advisories/refs/heads/generated/osv-export/2026/HSEC-2026-0007.json"
source
"https://github.com/haskell/security-advisories/blob/generated/osv-export/2026/HSEC-2026-0007.json"

Hackage / text-iso8601

Package

Name
text-iso8601
Purl
pkg:hackage/text-iso8601

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.1
Fixed
0.1.1.2

Affected versions

0.*
0.1
0.1.1
0.1.1.1

Database specific

human_link
"https://github.com/haskell/security-advisories/tree/main/advisories/published/2026/HSEC-2026-0007.md"
osv
"https://raw.githubusercontent.com/haskell/security-advisories/refs/heads/generated/osv-export/2026/HSEC-2026-0007.json"
source
"https://github.com/haskell/security-advisories/blob/generated/osv-export/2026/HSEC-2026-0007.json"