​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-8mhp-9r8c-whw4

Published

Last updated

https://images.chainguard.dev/security/CGA-8mhp-9r8c-whw4
Package

request-1277

Latest Update
Fixed
Fixed Version

0.1.89-r0

Aliases
  • CVE-2022-25857
  • GHSA-3mc7-4q67-w48m

Severity

7.5

High

CVSS V3

Summary

Uncontrolled Resource Consumption in snakeyaml

Description

The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images