GHSA-qcgx-crrx-38v5
GitHub Security Advisory
Denial of service in DataCommunicator class in Vaadin 8
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Missing check in `DataCommunicator` class in `com.vaadin:vaadin-server` versions 8.0.0 through 8.14.0 (Vaadin 8.0.0 through 8.14.0) allows authenticated network attacker to cause heap exhaustion by requesting too many rows of data.
Affected Packages
Maven
com.vaadin:vaadin-server
Affected versions:
8.0.6
(fixed in 8.14.1)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 1, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.