VYPR

YAML

by YAML Project

CVEs (4)

  • CVE-2023-2251HigApr 24, 2023
    risk 0.42cvss 7.5epss 0.01

    Uncaught Exception in GitHub repository eemeli/yaml prior to 2.0.0-5.

  • CVE-2022-3064HigDec 27, 2022
    risk 0.42cvss 7.5epss 0.02

    Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.

  • CVE-2022-28948HigMay 19, 2022
    risk 0.42cvss 7.5epss 0.04

    An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.

  • CVE-2021-4235MedDec 27, 2022
    risk 0.29cvss 5.5epss 0.00

    Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.