GHSA-4xcc-23fx-w2wj
UNKNOWNParserConfig::maxevents, maxnodes, maxtotalscalarbytes, maxmergekeys, aliasanchorratio and the alias jump factor were enforced only by the two Value loaders. A typed target with a default-shaped configuration is served by the streaming deserializer, which never read those fields, so tightening any of them had no effect on fromstr:: for a struct target. The default document-length, depth and alias-count caps were enforced on every path, so no input was unbounded; the gap affects callers who tightened the other budgets for hostile input.
Version 0.0.53 charges every budget on the streaming path as well and adds cross-path parity tests.
Users who cannot upgrade can deserialize into noyalib::Value first and convert with fromvalue, or rely on maxdocumentlength and maxdepth, which were always applied on every path.