Inefficient algorithmic complexity in DecodeFromBytes function in com.upokecenter.cbor Java implementation of Concise Binary Object Representation (CBOR) versions 4.0.0 to 4.5.1 allows an attacker to cause a denial of service by passing a maliciously crafted input. Depending on an application's use of this library, this may be a remote attacker.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/23xxx/CVE-2024-23684.json",
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-407"
]
}"2026-07-22T03:15:31Z"
[
{
"signature_version": "v1",
"target": {
"file": "src/main/java/com/upokecenter/cbor/CBORObject.java"
},
"id": "CVE-2024-23684-9184b715",
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"245892753497545230889079758148533917264",
"315323011616642422117914166067564514355",
"331648540739023347659894369769830188336",
"108298526331740189779353926158578726047",
"93474761964609928850723666233524642066"
]
},
"source": "https://github.com/peteroupc/cbor-java/commit/626acf4abee0225a11b45e1c3e28502c75573b15"
},
{
"signature_version": "v1",
"target": {
"file": "src/main/java/com/upokecenter/cbor/CBORObject.java",
"function": "MapCompare"
},
"id": "CVE-2024-23684-ef607bf4",
"signature_type": "Function",
"deprecated": false,
"digest": {
"function_hash": "295978138187162415375781255315036520609",
"length": 1001.0
},
"source": "https://github.com/peteroupc/cbor-java/commit/626acf4abee0225a11b45e1c3e28502c75573b15"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-23684.json"