Vulnerabilities > Yaml Project

DATE CVE VULNERABILITY TITLE RISK
2023-04-24 CVE-2023-2251 Uncaught Exception vulnerability in Yaml Project Yaml
Uncaught Exception in GitHub repository eemeli/yaml prior to 2.0.0-5.
network
low complexity
yaml-project CWE-248
7.5
2022-12-27 CVE-2021-4235 Unspecified vulnerability in Yaml Project Yaml
Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources.
local
low complexity
yaml-project
5.5
2022-12-27 CVE-2022-3064 Resource Exhaustion vulnerability in Yaml Project Yaml
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.
network
low complexity
yaml-project CWE-400
7.5
2022-05-19 CVE-2022-28948 Deserialization of Untrusted Data vulnerability in multiple products
An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.
network
low complexity
yaml-project netapp CWE-502
7.5