Loading
Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
Use CWE-121, Xstream vendor hub and Xstream product page to widen CVE-2022-40152 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-39152, CVE-2021-39150 and CVE-2021-39154 for nearby disclosures in the same product family.