Skip to content

3.3.3

Choose a tag to compare

@Spomky Spomky released this 31 Aug 16:19
· 65 commits to 3.5.x since this release
3.3.3
693f6ed

Hardening

The decoder now bounds the nesting depth of the data it parses: anything nested deeper than Decoder::DEFAULT_MAX_DEPTH (1000 levels) is rejected with an InvalidArgumentException instead of being turned into an object graph deep enough to crash the process when it is released. Nested arrays, maps, tag chains and indefinite-length containers all count towards that limit, which is configurable as the third argument of Decoder::create():

// Recommended when decoding data from an untrusted source
$decoder = Decoder::create(null, null, 32);

Reported by Ivan Tse. Thanks!


Release Notes for 3.3.3

3.3.3

bug