Repository navigation
3.3.3
Hardening
The decoder now bounds the nesting depth of the data it parses: anything nested deeper than Decoder::DEFAULT_MAX_DEPTH (1000 levels) is rejected with an InvalidArgumentException instead of being turned into an object graph deep enough to crash the process when it is released. Nested arrays, maps, tag chains and indefinite-length containers all count towards that limit, which is configurable as the third argument of Decoder::create():
// Recommended when decoding data from an untrusted source
$decoder = Decoder::create(null, null, 32);Reported by Ivan Tse. Thanks!
Release Notes for 3.3.3
3.3.3
-
Total issues resolved: 0
-
Total pull requests resolved: 2
-
Total contributors: 1
-
143: fix(decoder): limit the nesting depth of the decoded data thanks to @Spomky