serde serde_yaml 0.6.0 to 0.8.3 is affected by: Uncontrolled Recursion. The impact is: Denial of service by aborting. The component is: from_* functions (all deserialization functions). The attack vector is: Parsing a malicious YAML file. The fixed version is: 0.8.4 and later.
[
{
"product": "serde_yaml",
"vendor": "serde",
"versions": [
{
"status": "affected",
"version": "0.6.0 to 0.8.3 [fixed: 0.8.4 and later]"
}
]
}
]