CVE-2022-3064

HIGH7.5EPSS 2.2%

yaml package for Go can consume excessive amounts of CPU or memory

Published: 12/28/2022Modified: 2/4/2026
Also known as:GHSA-6q6q-88xp-6f2rCGA-47qj-6jjg-4g9fGO-2022-0956

Description

Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (13)