{"id":"GHSA-c24f-2j3g-rg48","summary":"kaml has potential denial of service while parsing input with anchors and aliases ","details":"### Impact\nApplications that use kaml to parse untrusted input containing anchors and aliases may consume excessive memory and crash.\n\n### Patches\nVersion 0.53.0 and later default to refusing to parse YAML documents containing anchors and aliases.\n\n### Workarounds\nNone.\n\n### References\nWikipedia has an explanation of this class of vulnerability: [billion laughs attack](https://en.wikipedia.org/wiki/Billion_laughs_attack)\n\n### Acknowledgements\nThank you to @gdude2002 for reporting this issue.","aliases":["CVE-2023-28118"],"modified":"2023-11-08T04:12:09.233283Z","published":"2023-03-20T21:26:59Z","database_specific":{"github_reviewed_at":"2023-03-20T21:26:59Z","nvd_published_at":"2023-03-20T13:15:00Z","cwe_ids":["CWE-776"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/charleskorn/kaml/security/advisories/GHSA-c24f-2j3g-rg48"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-28118"},{"type":"WEB","url":"https://github.com/charleskorn/kaml/commit/5f82a2d7e00bfc307afca05d1dc4d7c50593531a"},{"type":"PACKAGE","url":"https://github.com/charleskorn/kaml"},{"type":"WEB","url":"https://github.com/charleskorn/kaml/releases/tag/0.53.0"}],"affected":[{"package":{"name":"com.charleskorn.kaml:kaml","ecosystem":"Maven","purl":"pkg:maven/com.charleskorn.kaml/kaml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.53.0"}]}],"versions":["0.1.0","0.10.0","0.11.0","0.12.0","0.13.0","0.14.0","0.15.0","0.16.1","0.17.0","0.18.0","0.18.1","0.19.0","0.2.1","0.20.0","0.21.0","0.22.0","0.23.0","0.24.0","0.25.0","0.26.0","0.27.0","0.28.0","0.28.1","0.28.2","0.28.3","0.29.0","0.3.0","0.30.0","0.31.0","0.32.0","0.33.0","0.34.0","0.35.0","0.35.1","0.35.2","0.35.3","0.36.0","0.37.0","0.38.0","0.39.0","0.39.1","0.4.0","0.40.0","0.41.0","0.42.0","0.43.0","0.44.0","0.45.0","0.46.0","0.47.0","0.48.0","0.49.0","0.5.0","0.50.0","0.51.0","0.52.0","0.6.0","0.7.0","0.8.0","0.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-c24f-2j3g-rg48/GHSA-c24f-2j3g-rg48.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}