Unrated severityNVD Advisory· Published Mar 6, 2026· Updated Mar 6, 2026
MarkUs: YAML alias (‘billion laughs’) DoS in config upload
CVE-2026-27807
Description
MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs allows course instructors to upload YAML files to create/update various entities (e.g., assignment settings). These YAML files are parsed with aliases enabled. This issue has been patched in version 2.9.4.
Affected products
2- MarkUsProject/Markusv5Range: < 2.9.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/MarkUsProject/Markus/releases/tag/v2.9.4mitrex_refsource_MISC
- github.com/MarkUsProject/Markus/security/advisories/GHSA-m9rx-85mx-q9h6mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.