VDB
Sign up
MEDIUM5.5

GHSA-r88r-gmrh-7j83

YAML Go package vulnerable to denial of service

Quick fix

GHSA-r88r-gmrh-7j83 — gopkg.in/yaml.v2: upgrade to the fixed version with the command below.

go get gopkg.in/yaml.v2@v2.2.3

Details

Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/gopkg.in/yaml.v2
Introduced in: 0Fixed in: 2.2.3
Fixgo get gopkg.in/yaml.v2@v2.2.3
Go/github.com/go-yaml/yaml
Introduced in: 0

No fixed version published yet for github.com/go-yaml/yaml (go modules). Pin to a known-safe version or switch to an alternative.

References