Vendors · yaml project
Products (1)
Recent Vulnerabilities
View all 4 →CVE-2023-2251HIGH 7.5
Uncaught Exception in GitHub repository eemeli/yaml prior to 2.0.0-5.
CVE-2022-3064HIGH 7.5
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.
CVE-2021-4235MEDIUM 5.5
Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.
CVE-2022-28948HIGH 7.5
An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.
