server.cpp in Monopd 0.9.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a string containing a large number of characters that are escaped when Monopd produces XML output.
{ "urgency": "low" }
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2006-1046.json"