Loading HuntDB...

GHSA-qcgx-crrx-38v5

GitHub Security Advisory

Denial of service in DataCommunicator class in Vaadin 8

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Missing check in `DataCommunicator` class in `com.vaadin:vaadin-server` versions 8.0.0 through 8.14.0 (Vaadin 8.0.0 through 8.14.0) allows authenticated network attacker to cause heap exhaustion by requesting too many rows of data.

Affected Packages

Maven com.vaadin:vaadin-server
Affected versions: 8.0.6 (fixed in 8.14.1)

Related CVEs

Key Information

GHSA ID
GHSA-qcgx-crrx-38v5
Published
October 13, 2021 6:54 PM
Last Modified
May 15, 2024 5:13 AM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
com.vaadin:vaadin-server
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 1, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.