Package impact

golang Go / gopkg.in/yaml.v2

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-3064 medium 5.5 3y ago RHSA-2024:10784: rhc security update (Moderate)
CVE-2021-4235 unknown 4y ago Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.
CVE-2019-11254 unknown 5y ago The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to c…