Lucene search

K
osvGoogleOSV:GO-2020-0036
HistoryApr 14, 2021 - 8:04 p.m.

Excessive resource consumption in YAML parsing in gopkg.in/yaml.v2

2021-04-1420:04:52
Google
osv.dev
18

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.0%

Due to unbounded aliasing, a crafted YAML file can cause consumption of significant system resources. If parsing user supplied input, this may be used as a denial of service vector.

CPENameOperatorVersion
gopkg.in/yaml.v2lt2.2.8