Back

MEDIUM

DoS in SnakeYAML

Published Sep 5, 2022

Description

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.

Affected products

Remediation

Red Hat statement

Red Hat Build of Quarkus is not affected by this issue as it already includes the fixed version. Satellite component Candlepin does not directly use snakeyaml, so it is not affected. Regardless, an update with the latest, unaffected snakeyaml version will be provided at next release.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Google
Published Sep 5, 2022
Updated Apr 21, 2025
Reserved Aug 25, 2022
CISA Vulnrichment
Updated Apr 21, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 5, 2022
GHSA-98WM-3W3Q-MW94