{"id":"GHSA-39vw-qp34-rmwf","summary":"Uncontrolled recursion leads to abort in deserialization","details":"Affected versions of this crate did not properly check for recursion while deserializing aliases. This allows an attacker to make a YAML file with an alias referring to itself causing an abort. The flaw was corrected by checking the recursion depth.\n","aliases":["RUSTSEC-2018-0005"],"modified":"2023-11-08T04:14:33.650192Z","published":"2021-08-25T21:00:18Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-08-06T17:45:03Z","nvd_published_at":null,"cwe_ids":["CWE-674"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/dtolnay/serde-yaml/pull/105"},{"type":"WEB","url":"https://github.com/dtolnay/serde-yaml/commit/b93aff6e904cffbbfd1f421b82f6dcc5ca19a4fd"},{"type":"PACKAGE","url":"https://github.com/dtolnay/serde-yaml"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2018-0005.html"}],"affected":[{"package":{"name":"serde_yaml","ecosystem":"crates.io","purl":"pkg:cargo/serde_yaml"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.6.0-rc1"},{"fixed":"0.8.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-39vw-qp34-rmwf/GHSA-39vw-qp34-rmwf.json"}}],"schema_version":"1.9.0"}