CVE-2023-28118
Summary
| CVE | CVE-2023-28118 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-20 13:15:00 UTC |
| Updated | 2023-03-24 18:00:00 UTC |
| Description | kaml provides YAML support for kotlinx.serialization. Prior to version 0.53.0, applications that use kaml to parse untrusted input containing anchors and aliases may consume excessive memory and crash. Version 0.53.0 and later default to refusing to parse YAML documents containing anchors and aliases. There are no known workarounds. |
Risk And Classification
Problem Types: CWE-776
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Kaml Project | Kaml | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Default to not parsing anchors and aliases to prevent "billion laughs… · charleskorn/kaml@5f82a2d · GitHub | MISC | github.com | |
| Potential denial of service while parsing input with anchors and aliases · Advisory · charleskorn/kaml · GitHub | MISC | github.com | |
| Release 0.53.0 · charleskorn/kaml · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.