CVE-2023-28118
HIGHkaml < 0.53.0 - Denial of Service via YAML Anchors and Aliases
Title source: llmDescription
kaml provides YAML support for kotlinx.serialization. Prior to version 0.53.0, applications that use kaml to parse untrusted input containing anchors and aliases may consume excessive memory and crash. Version 0.53.0 and later default to refusing to parse YAML documents containing anchors and aliases. There are no known workarounds.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/charleskorn/kaml/security/advisories/GHSA-c24f-2j3g-rg48
Patch x_refsource_misc
https://github.com/charleskorn/kaml/commit/5f82a2d7e00bfc307afca05d1dc4d7c50593531a
Release Notes x_refsource_misc
https://github.com/charleskorn/kaml/releases/tag/0.53.0
Scores
CVSS v3
7.5
EPSS
0.0097
EPSS Percentile
57.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-776
Status
published
Products (2)
com.charleskorn.kaml/kaml
0 - 0.53.0Maven
kaml_project/kaml
< 0.53.0
Published
Mar 20, 2023
Tracked Since
Feb 18, 2026