PT-2022-6917 · Snakeyaml+3 · Snakeyaml+3

Published

2022-09-05

·

Updated

2026-05-18

·

CVE-2022-38752

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions snakeYAML (affected versions not specified)
Description The issue is related to the parsing of untrusted YAML files, which may lead to Denial of Service attacks. If the parser is running on user-supplied input, an attacker may supply content that causes the parser to crash by stack-overflow. This can be exploited by a remote attacker to cause a service disruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of snakeYAML for parsing untrusted YAML files to minimize the risk of exploitation. Avoid using snakeYAML to parse user-supplied input until the issue is resolved.

DoS

Stack Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-05610
CLEANSTART-2026-GH89210
CVE-2022-38752
GHSA-9W3M-GQGF-C4P9
OESA-2023-1162
OESA-2023-1163
OESA-2023-1164
OESA-2023-1165
OPENSUSE-SU-2022_3397-1
OPENSUSE-SU-2024:12308-1
RHSA-2023:1512
RHSA-2023:1513
RHSA-2023:1514
RHSA-2023:2097
RHSA-2023:2705
RHSA-2023:2706
RHSA-2023:2707
RLSA-2023:2097
SUSE-SU-2022:3397-1
SUSE-SU-2022:3560-1

Affected Products

Debian
Rocky Linux
Suse
Snakeyaml