Versions before 4.5.1 of the CBOR parsing library are vulnerable to a denial of service attack, see advisory https://github.com/peteroupc/CBOR-Java/security/advisories/GHSA-fj2w-wfgv-mwq6