AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-2253

MEDIUM · CVSS 6.5 EPSS 0.94%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-06-06 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2023-2253
Severity
MEDIUM
CVSS
6.5
EPSS
0.94%

Original NVD Description

A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array, possibly causing a denial of service through excessive use of memory.