Include original message

A quick thought on the array size filter:

The system creates an array with a size read from the stream.

If Mallory sends a multidimensional array in the stream, then Mallory can 
consume all jvm memory without exceeding the array size limit or the stream 
data limit.

We also need an array combined length limit.

Thanks,

Peter.

Sent from my Samsung device.
 

Reply via email to