Junglewise Threat Intelligence

CVE-2026-33320: GO-2026-4768 - Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service in github.com/tomwright/dasel

CVE-2026-33320 · Severity: low · CVSS 3.1 · Published 2026-03-23

Technologies: github.com/tomwright/dasel (Go), github.com/tomwright/dasel/v2 (Go), github.com/tomwright/dasel/v3 (Go). Vendors: Go.

Executive brief

Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service in github.com/tomwright/dasel

Affected products

  • Go github.com/tomwright/dasel
  • Go github.com/tomwright/dasel/v2
  • Go github.com/tomwright/dasel/v3

Related threats