{"schema_version":"1.9.0","id":"GHSA-c4r9-r8fh-9vj2","published":"2022-09-06T00:00:27Z","modified":"2026-09-10T03:49:45.518714221Z","aliases":["CVE-2022-38749"],"summary":"snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write","details":"Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.","affected":[{"package":{"name":"org.yaml:snakeyaml","ecosystem":"Maven","purl":"pkg:maven/org.yaml/snakeyaml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.31"}]}],"versions":["1.10","1.11","1.12","1.13","1.14","1.15","1.16","1.17","1.18","1.19","1.20","1.21","1.22","1.23","1.24","1.25","1.26","1.27","1.28","1.29","1.30","1.4","1.5","1.6","1.7","1.8","1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-c4r9-r8fh-9vj2/GHSA-c4r9-r8fh-9vj2.json"}},{"package":{"name":"be.cylab:snakeyaml","ecosystem":"Maven","purl":"pkg:maven/be.cylab/snakeyaml"},"versions":["1.25.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-c4r9-r8fh-9vj2/GHSA-c4r9-r8fh-9vj2.json"}},{"package":{"name":"com.alipay.sofa.acts:acts-common-util","ecosystem":"Maven","purl":"pkg:maven/com.alipay.sofa.acts/acts-common-util"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-c4r9-r8fh-9vj2/GHSA-c4r9-r8fh-9vj2.json"}},{"package":{"name":"io.prometheus.jmx:jmx_prometheus_httpserver","ecosystem":"Maven","purl":"pkg:maven/io.prometheus.jmx/jmx_prometheus_httpserver"},"versions":["0.17.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-c4r9-r8fh-9vj2/GHSA-c4r9-r8fh-9vj2.json"}},{"package":{"name":"io.prometheus.jmx:jmx_prometheus_httpserver_java6","ecosystem":"Maven","purl":"pkg:maven/io.prometheus.jmx/jmx_prometheus_httpserver_java6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.18.0"}]}],"versions":["0.17.0","0.17.1","0.17.2","0.18.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-c4r9-r8fh-9vj2/GHSA-c4r9-r8fh-9vj2.json"}},{"package":{"name":"org.testifyproject.external:external-snakeyaml","ecosystem":"Maven","purl":"pkg:maven/org.testifyproject.external/external-snakeyaml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.0.6"}]}],"versions":["0.9.5","0.9.6","0.9.7","0.9.8","0.9.9","1.0.0","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-c4r9-r8fh-9vj2/GHSA-c4r9-r8fh-9vj2.json"}},{"package":{"name":"pl.droidsonroids.yaml:snakeyaml","ecosystem":"Maven","purl":"pkg:maven/pl.droidsonroids.yaml/snakeyaml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.18.2"}]}],"versions":["1.18-android","1.18.1","1.18.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-c4r9-r8fh-9vj2/GHSA-c4r9-r8fh-9vj2.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-38749"},{"type":"WEB","url":"https://arxiv.org/pdf/2306.05534.pdf"},{"type":"PACKAGE","url":"https://bitbucket.org/snakeyaml/snakeyaml"},{"type":"WEB","url":"https://bitbucket.org/snakeyaml/snakeyaml/issues/525/got-stackoverflowerror-for-many-open"},{"type":"WEB","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47024"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2022/10/msg00001.html"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202305-28"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20240315-0010"}],"database_specific":{"cwe_ids":["CWE-121","CWE-787"],"github_reviewed":true,"github_reviewed_at":"2022-09-15T03:27:43Z","nvd_published_at":"2022-09-05T10:15:00Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}