From 5f3663fdc39746c77e3cfec42ac63d6d9b4982e2 Mon Sep 17 00:00:00 2001 From: Li-yao Xia Date: Thu, 17 Sep 2026 23:05:41 +0200 Subject: [PATCH] Update changelog to downgrade severity of text-iso8601 year parsing issue --- changelog.md | 9 ++++++++- text-iso8601/changelog.md | 13 ++++++++++--- 2 files changed, 18 insertions(+), 4 deletions(-) diff --git a/changelog.md b/changelog.md index 1d2729ca..64099404 100644 --- a/changelog.md +++ b/changelog.md @@ -30,7 +30,14 @@ Fix a DoS vulnerability caused by parsing large numbers (advisory [HSEC-2026-000 rejecting more inputs. Error messages for `Ratio` and integral types are also slightly different due to reusing the same bounding logic. * In `text-iso8601-0.1.1.2` (backported from 0.2.0.0): - - (HSEC-2026-0007) Reject years of more than 15 digits. + - Reject years of more than 15 digits. + + This year parsing issue was previously reported as a DoS vulnerability in [HSEC-2026-0007](https://haskell.github.io/security-advisories/advisory/HSEC-2026-0007.html) + but [we later reevaluated it as not a DoS vulnerability](https://github.com/haskell/security-advisories/issues/339). + (The other vulnerability in aeson remains in that advisory.) + Indeed, years were parsed in time `O(n log n)` which is asymptotically + no slower than parsing integer literals (which happens on all JSON integers + regardless of the target type, unlike dates). ### 2.2.5.0 diff --git a/text-iso8601/changelog.md b/text-iso8601/changelog.md index 3d833603..d290b479 100644 --- a/text-iso8601/changelog.md +++ b/text-iso8601/changelog.md @@ -1,13 +1,20 @@ # 0.2.0.0 - 2026-05-21 -- Fix a DoS vulnerability caused by parsing large numbers (advisory [HSEC-2026-0007](https://haskell.github.io/security-advisories/advisory/HSEC-2026-0007.html)). Backported to 0.1.1.2, see below. - Accept 24:00:00 time of day. +- Fix parsers to reject years with more than 15 digits. + + This year parsing issue was previously reported as a DoS vulnerability in [HSEC-2026-0007](https://haskell.github.io/security-advisories/advisory/HSEC-2026-0007.html) + but [we later reevaluated it as not a DoS vulnerability](https://github.com/haskell/security-advisories/issues/339). + (The other vulnerability in aeson remains in that advisory.) + Indeed, years were parsed in time `O(n log n)` which is asymptotically + no slower than parsing integer literals (which happens on all JSON integers + regardless of the target type, unlike dates). # 0.1.1.2 - 2026-08-29 (backport from 0.2.0.0) -Fix a DoS vulnerability caused by parsing large numbers (advisory [HSEC-2026-0007](https://haskell.github.io/security-advisories/advisory/HSEC-2026-0007.html)). Backported from 0.2.0.0 to ease migration. +Backported from 0.2.0.0 to ease migration. -- (HSEC-2026-0007) Fix parsers to reject years with more than 15 digits +- Fix parsers to reject years with more than 15 digits. # 0.1.1.1