Skip to content

v0.11.0

Choose a tag to compare

@rybakit rybakit released this 25 Sep 21:21
· 2 commits to master since this release
  • Added a default limit of 128 nested arrays and maps during unpacking. The limit can be customized through BufferUnpacker::unpack(), unpackArray(), and unpackMap().
  • Reject invalid timestamp extension payload lengths to prevent reading beyond the payload.
  • Require 64-bit PHP.

Credit: Thanks to Diptendu Mohan Kar for reporting the vulnerabilities.

Full Changelog: v0.10.0...v0.11.0