gopkg.in/yaml.v2
Activity
- Latest release
- 5y ago
- Total releases
- 14
- Cadence
- ~32 days
- Last 12 months
- 0
Details
- First release
- Jan 09, 2018
| Version | Released | |
|---|---|---|
v2.4.0
minor
|
v2.4.0
minor
Dependencies (1)
|
|
v2.3.0
minor
|
v2.3.0
minor
Dependencies (1)
|
|
v2.2.8
patch
|
v2.2.8
patch
Dependencies (1)
|
|
v2.2.7
patch
1 CVE
CVE-2019-11254
GHSA-wxc4-f4m6-wwqv
GO-2020-0036
Dec 20, 2021
Excessive Platform Resource Consumption within a Loop in Kubernetes
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML. Fixed in
2.2.8
References
Updated Sep 10, 2026 · Source: OSV.dev |
v2.2.7
patch
Dependencies (1)
|
|
v2.2.6
patch
1 CVE
CVE-2019-11254
GHSA-wxc4-f4m6-wwqv
GO-2020-0036
Dec 20, 2021
Excessive Platform Resource Consumption within a Loop in Kubernetes
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML. Fixed in
2.2.8
References
Updated Sep 10, 2026 · Source: OSV.dev |
v2.2.6
patch
Dependencies (1)
|
|
v2.2.5
patch
1 CVE
CVE-2019-11254
GHSA-wxc4-f4m6-wwqv
GO-2020-0036
Dec 20, 2021
Excessive Platform Resource Consumption within a Loop in Kubernetes
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML. Fixed in
2.2.8
References
Updated Sep 10, 2026 · Source: OSV.dev |
v2.2.5
patch
Dependencies (1)
|
|
v2.2.4
patch
1 CVE
CVE-2019-11254
GHSA-wxc4-f4m6-wwqv
GO-2020-0036
Dec 20, 2021
Excessive Platform Resource Consumption within a Loop in Kubernetes
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML. Fixed in
2.2.8
References
Updated Sep 10, 2026 · Source: OSV.dev |
v2.2.4
patch
Dependencies (1)
|
|
v2.2.3
patch
2 CVEs
CVE-2022-3064
GHSA-6q6q-88xp-6f2r
GO-2022-0956
Dec 28, 2022
yaml package for Go can consume excessive amounts of CPU or memory
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory Fixed in
2.2.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11254
GHSA-wxc4-f4m6-wwqv
GO-2020-0036
Dec 20, 2021
Excessive Platform Resource Consumption within a Loop in Kubernetes
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML. Fixed in
2.2.8
References
Updated Sep 10, 2026 · Source: OSV.dev |
v2.2.3
patch
Dependencies (1)
|
|
v2.2.2
patch
3 CVEs
CVE-2021-4235
GHSA-r88r-gmrh-7j83
GO-2021-0061
Dec 28, 2022
YAML Go package vulnerable to denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector. Fixed in
2.2.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-3064
GHSA-6q6q-88xp-6f2r
GO-2022-0956
Dec 28, 2022
yaml package for Go can consume excessive amounts of CPU or memory
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory Fixed in
2.2.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11254
GHSA-wxc4-f4m6-wwqv
GO-2020-0036
Dec 20, 2021
Excessive Platform Resource Consumption within a Loop in Kubernetes
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML. Fixed in
2.2.8
References
Updated Sep 10, 2026 · Source: OSV.dev |
v2.2.2
patch
Dependencies (1)
|
|
v2.2.1
patch
3 CVEs
CVE-2021-4235
GHSA-r88r-gmrh-7j83
GO-2021-0061
Dec 28, 2022
YAML Go package vulnerable to denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector. Fixed in
2.2.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-3064
GHSA-6q6q-88xp-6f2r
GO-2022-0956
Dec 28, 2022
yaml package for Go can consume excessive amounts of CPU or memory
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory Fixed in
2.2.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11254
GHSA-wxc4-f4m6-wwqv
GO-2020-0036
Dec 20, 2021
Excessive Platform Resource Consumption within a Loop in Kubernetes
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML. Fixed in
2.2.8
References
Updated Sep 10, 2026 · Source: OSV.dev |
v2.2.1
patch
Dependencies (1)
|
|
v2.2.0
minor
3 CVEs
CVE-2021-4235
GHSA-r88r-gmrh-7j83
GO-2021-0061
Dec 28, 2022
YAML Go package vulnerable to denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector. Fixed in
2.2.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-3064
GHSA-6q6q-88xp-6f2r
GO-2022-0956
Dec 28, 2022
yaml package for Go can consume excessive amounts of CPU or memory
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory Fixed in
2.2.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11254
GHSA-wxc4-f4m6-wwqv
GO-2020-0036
Dec 20, 2021
Excessive Platform Resource Consumption within a Loop in Kubernetes
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML. Fixed in
2.2.8
References
Updated Sep 10, 2026 · Source: OSV.dev |
v2.2.0
minor
Dependencies (1)
|
|
v2.1.1
patch
3 CVEs
CVE-2021-4235
GHSA-r88r-gmrh-7j83
GO-2021-0061
Dec 28, 2022
YAML Go package vulnerable to denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector. Fixed in
2.2.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-3064
GHSA-6q6q-88xp-6f2r
GO-2022-0956
Dec 28, 2022
yaml package for Go can consume excessive amounts of CPU or memory
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory Fixed in
2.2.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11254
GHSA-wxc4-f4m6-wwqv
GO-2020-0036
Dec 20, 2021
Excessive Platform Resource Consumption within a Loop in Kubernetes
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML. Fixed in
2.2.8
References
Updated Sep 10, 2026 · Source: OSV.dev |
v2.1.1
patch
Dependencies (1)
|
|
v2.1.0
minor
3 CVEs
CVE-2021-4235
GHSA-r88r-gmrh-7j83
GO-2021-0061
Dec 28, 2022
YAML Go package vulnerable to denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector. Fixed in
2.2.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-3064
GHSA-6q6q-88xp-6f2r
GO-2022-0956
Dec 28, 2022
yaml package for Go can consume excessive amounts of CPU or memory
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory Fixed in
2.2.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11254
GHSA-wxc4-f4m6-wwqv
GO-2020-0036
Dec 20, 2021
Excessive Platform Resource Consumption within a Loop in Kubernetes
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML. Fixed in
2.2.8
References
Updated Sep 10, 2026 · Source: OSV.dev |
v2.1.0
minor
|
|
v2.0.0
initial
3 CVEs
CVE-2021-4235
GHSA-r88r-gmrh-7j83
GO-2021-0061
Dec 28, 2022
YAML Go package vulnerable to denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector. Fixed in
2.2.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-3064
GHSA-6q6q-88xp-6f2r
GO-2022-0956
Dec 28, 2022
yaml package for Go can consume excessive amounts of CPU or memory
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory Fixed in
2.2.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11254
GHSA-wxc4-f4m6-wwqv
GO-2020-0036
Dec 20, 2021
Excessive Platform Resource Consumption within a Loop in Kubernetes
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML. Fixed in
2.2.8
References
Updated Sep 10, 2026 · Source: OSV.dev |
v2.0.0
initial
|