Yaml ProjectCVEs & Vulnerabilities
4 CVEs affecting Yaml Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
4 CVEs→ All vendors
Most Affected Products
yaml 4
CVE-2023-2251HIGH
Uncaught Exception in GitHub repository eemeli/yaml prior to 2.0.0-5.
24 Apr 2023
7.5
CVSS
CVE-2022-3064HIGH
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.
28 Dec 2022
7.5
CVSS
CVE-2021-4235MEDIUM
Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.
28 Dec 2022
5.5
CVSS
CVE-2022-28948HIGH
An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.
19 May 2022
7.5
CVSS
← PrevPage 1 / 1Next →