GHSA-jgvr-6x5w-hx5w: Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
Feeding a KCL program that wraps an expression in deep, unnecessary parentheses triggers the parser’s recursive expression -> unnecessarily_bracketed -> expression path. With enough nesting, the call stack grows until it exceeds the process stack limit, causing a stack overflow.
References
Code Behaviors & Features
Detect and mitigate GHSA-jgvr-6x5w-hx5w with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →