Improper Input Validation in net.sf.robocode:robocode.host allows for external service interaction
Critical severity
GitHub Reviewed
Published
Apr 2, 2019
to the GitHub Advisory Database
•
Updated Dec 22, 2025
Description
Published by the National Vulnerability Database
Mar 30, 2019
Published to the GitHub Advisory Database
Apr 2, 2019
Reviewed
Jun 16, 2020
Last updated
Dec 22, 2025
Robocode through 1.9.3.5 allows remote attackers to cause external service interaction (DNS), as demonstrated by a query for a unique subdomain name within an attacker-controlled DNS zone, because of a .openStream call within java.net.URL.
References