CVE-2023-37475 is a denial-of-service vulnerability affecting the Hamba avro Go language encoder/decoder, specifically the avro_project avro product. A specially crafted string passed to the Unmarshal() function can trigger an out-of-memory error, causing the application to crash. This high-severity vulnerability (CVSS 7.5) has a low attack complexity and requires no user interaction, allowing unauthenticated attackers to achieve a complete denial of service. While a fix is available in version 2.13.0, there are currently no known workarounds, active exploits, or public exploit code, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.13.0CPE matchmatch criteria | cpe:2.3:a:avro_project:avro:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.