{"schema_version":"1.7.3","id":"GO-2022-0956","published":"2022-08-29T22:15:46Z","modified":"2026-02-04T02:18:50.393856Z","aliases":["CVE-2022-3064","GHSA-6q6q-88xp-6f2r"],"related":["CGA-47qj-6jjg-4g9f","RHSA-2023:1014","RHSA-2023:1275","RHSA-2023:6346","RHSA-2023:6938","RHSA-2023:6939","RHSA-2024:10759","RHSA-2024:10784","RHSA-2024:4443"],"summary":"Excessive resource consumption in gopkg.in/yaml.v2","details":"Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.","affected":[{"package":{"name":"gopkg.in/yaml.v2","ecosystem":"Go","purl":"pkg:golang/gopkg.in/yaml.v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.2.4"}]}],"ecosystem_specific":{"imports":[{"path":"gopkg.in/yaml.v2","symbols":["Decoder.Decode","Unmarshal","UnmarshalStrict","decoder.unmarshal","yaml_parser_increase_flow_level","yaml_parser_roll_indent"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2022-0956.json"}}],"references":[{"type":"FIX","url":"https://github.com/go-yaml/yaml/commit/f221b8435cfb71e54062f6c6e99e9ade30b124d5"},{"type":"WEB","url":"https://github.com/go-yaml/yaml/releases/tag/v2.2.4"}],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2022-0956"}}