Skip to content

6.8.6

Compare
Choose a tag to compare
@dcodeIO dcodeIO released this 26 Feb 11:47
· 182 commits to master since this release

This is a security patch:

  • Fixes typeRefRe used in the parser (1.X-6.8.5) being vulnerable to ReDoS as reported by James Davis. Relevant where a user is allowed to provide .proto sources for parsing. Applications using trusted .proto definitions, JSON descriptors or static code exclusively are not affected.