But for now, what is the risk in allowing the newer version of text-iso8601 (overriding the bounds)? It seems to me that the risk of anything breaking when overriding the bounds isn’t that big. Not when considering that the DoS vulnerability should then be solved.
If you are shipping or operating any web service that exposes an endpoint using this.. that service and possibly others on the same machine, can be crashed at will by a crafted request, if I understand rightly ?
Yes. While I haven’t verified, it looks like a terrible vulnerability. It’s a shame this important package hasn’t been updated, since Stackage LTS 25 is going to be released soon. It likely means that many users will be vulnerable for another year.