if you allow a JSON parser use all of memory to go deep, you know what attackers will do... As other commenters mentioned JSON spec allows setting a limit on the depth.
"[0, 0, 0, 0, 0, <...gigabytes of zeros>, 0 0, 0, 0]"
So you need to limit the overall input size regardless of whether you already have a depth limit in place.
An application that does not limit the maximum size of its input in bytes is vulnerable, one that does is not. This is completely independent of the JSON parser.