Executive brief
Excessive resource consumption in YAML parsing in gopkg.in/yaml.v2
Affected products
- Go gopkg.in/yaml.v2
- Go github.com/go-yaml/yaml
Junglewise Threat Intelligence
CVE-2019-11254 · Severity: low · CVSS 3.1 · Published 2021-04-14
Technologies: gopkg.in/yaml.v2 (Go). Vendors: Go.
Excessive resource consumption in YAML parsing in gopkg.in/yaml.v2