Vendor
YAML Project
Products
1
CVEs
4
Across products
4
Status
Private
Products
1- 4 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-2251 | Hig | 0.42 | 7.5 | 0.01 | Apr 24, 2023 | Uncaught Exception in GitHub repository eemeli/yaml prior to 2.0.0-5. | ||
| CVE-2022-3064 | Hig | 0.42 | 7.5 | 0.02 | Dec 27, 2022 | Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory. | ||
| CVE-2022-28948 | Hig | 0.42 | 7.5 | 0.04 | May 19, 2022 | An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input. | ||
| CVE-2021-4235 | Med | 0.29 | 5.5 | 0.00 | Dec 27, 2022 | Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector. |
- risk 0.42cvss 7.5epss 0.01
Uncaught Exception in GitHub repository eemeli/yaml prior to 2.0.0-5.
- risk 0.42cvss 7.5epss 0.02
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.
- risk 0.42cvss 7.5epss 0.04
An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.
- risk 0.29cvss 5.5epss 0.00
Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.