CVE Published: 27/12/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: Go |
Vendor: gopkg.in/yaml.v2 |
Product: gopkg.in/yaml.v2 Status : PUBLISHED
CVE-2021-4235 Description
Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.