← Back

Snakeyaml Project

snakeyaml_project

8 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Snakeyaml
snakeyaml

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Snakeyaml Project
1Snakeyaml
Jun 18, 2025
Dec 1, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml...Show more
SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.Show less
2Fedoraproject
Snakeyaml Project
2Fedora
Snakeyaml
Nov 21, 2024
Nov 11, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by...Show more
Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack.Show less
1Snakeyaml Project
1Snakeyaml
Nov 21, 2024
Sep 5, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack...Show more
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack-overflow.Show less
2Debian
Snakeyaml Project
2Debian Linux
Snakeyaml
Nov 21, 2024
Sep 5, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack...Show more
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.Show less
2Debian
Snakeyaml Project
2Debian Linux
Snakeyaml
Nov 21, 2024
Sep 5, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack...Show more
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.Show less
2Debian
Snakeyaml Project
2Debian Linux
Snakeyaml
Nov 21, 2024
Sep 5, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack...Show more
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.Show less
2Debian
Snakeyaml Project
2Debian Linux
Snakeyaml
Nov 21, 2024
Aug 30, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.
4Fedoraproject
OracleQuarkus+1 more
4Fedora
Peoplesoft Enterprise Pt PeopletoolsQuarkus+1 more
Nov 21, 2024
Dec 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.