Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 8 additions & 1 deletion changelog.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,14 @@ Fix a DoS vulnerability caused by parsing large numbers (advisory [HSEC-2026-000
rejecting more inputs. Error messages for `Ratio` and integral types are also slightly different
due to reusing the same bounding logic.
* In `text-iso8601-0.1.1.2` (backported from 0.2.0.0):
- (HSEC-2026-0007) Reject years of more than 15 digits.
- Reject years of more than 15 digits.

This year parsing issue was previously reported as a DoS vulnerability in [HSEC-2026-0007](https://haskell.github.io/security-advisories/advisory/HSEC-2026-0007.html)
but [we later reevaluated it as not a DoS vulnerability](https://github.com/haskell/security-advisories/issues/339).
(The other vulnerability in aeson remains in that advisory.)
Indeed, years were parsed in time `O(n log n)` which is asymptotically
no slower than parsing integer literals (which happens on all JSON integers
regardless of the target type, unlike dates).

### 2.2.5.0

Expand Down
13 changes: 10 additions & 3 deletions text-iso8601/changelog.md
Original file line number Diff line number Diff line change
@@ -1,13 +1,20 @@
# 0.2.0.0 - 2026-05-21

- Fix a DoS vulnerability caused by parsing large numbers (advisory [HSEC-2026-0007](https://haskell.github.io/security-advisories/advisory/HSEC-2026-0007.html)). Backported to 0.1.1.2, see below.
- Accept 24:00:00 time of day.
- Fix parsers to reject years with more than 15 digits.

This year parsing issue was previously reported as a DoS vulnerability in [HSEC-2026-0007](https://haskell.github.io/security-advisories/advisory/HSEC-2026-0007.html)
but [we later reevaluated it as not a DoS vulnerability](https://github.com/haskell/security-advisories/issues/339).
(The other vulnerability in aeson remains in that advisory.)
Indeed, years were parsed in time `O(n log n)` which is asymptotically
no slower than parsing integer literals (which happens on all JSON integers
regardless of the target type, unlike dates).

# 0.1.1.2 - 2026-08-29 (backport from 0.2.0.0)

Fix a DoS vulnerability caused by parsing large numbers (advisory [HSEC-2026-0007](https://haskell.github.io/security-advisories/advisory/HSEC-2026-0007.html)). Backported from 0.2.0.0 to ease migration.
Backported from 0.2.0.0 to ease migration.

- (HSEC-2026-0007) Fix parsers to reject years with more than 15 digits
- Fix parsers to reject years with more than 15 digits.

# 0.1.1.1

Expand Down