{"id":"CVE-2023-24620","details":"An issue was discovered in Esoteric YamlBeans through 1.15. A crafted YAML document is able perform am XML Entity Expansion attack against YamlBeans YamlReader. By exploiting the Anchor feature in YAML, it is possible to generate a small YAML document that, when read, is expanded to a large size, causing CPU and memory consumption, such as a Java Out-of-Memory exception.","aliases":["GHSA-vj49-j7rc-h54f"],"modified":"2026-08-12T03:51:27.409468401Z","published":"2023-08-25T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/24xxx/CVE-2023-24620.json","unresolved_ranges":[{"extracted_events":[{"fixed":"1.15"}],"source":"DESCRIPTION"}],"cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://contrastsecurity.com"},{"type":"WEB","url":"https://github.com/Contrast-Security-OSS/yamlbeans/blob/main/SECURITY.md"},{"type":"WEB","url":"https://github.com/EsotericSoftware"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/24xxx/CVE-2023-24620.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-24620"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/esotericsoftware/yamlbeans","events":[{"introduced":"0"},{"last_affected":"3f1fcb516c940c362a5db475917820903331d170"}],"database_specific":{"cpe":"cpe:2.3:a:esotericsoftware:yamlbeans:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.15"}],"source":"CPE_RANGE"}}],"versions":["1.15","1.14","1.12","1.11","yamlbeans-1.09","yamlbeans-1.08"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-24620.json"}}],"schema_version":"1.9.0"}