Skibidi Java – The Infinite Loop in Java Collections; Edge Case to Java Universal DoS
ID: b9268d42-59d8-56a2-a505-f38ec1ca703a
STIX ID: report--b9268d42-59d8-56a2-a505-f38ec1ca703a
Feed Name: Checkmarx Zero
This report ("SkibidiJava") documents a DoS vulnerability in Java's core collections where circular references (for example, an ArrayList containing itself used as a HashMap key) cause infinite recursion and a StackOverflowError when deserialized; the document provides PoC code, describes real-world attack surfaces (untrusted deserialization of java.util types), and recommends mitigations such as input validation, class allowlisting, and custom deserializers to detect circular references.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
