Vulnerability CVE-2023-47163


Published: 2023-11-13

Description:
Remarshal prior to v0.17.1 expands YAML alias nodes unlimitedly, hence Remarshal is vulnerable to Billion Laughs Attack. Processing untrusted YAML files may cause a denial-of-service (DoS) condition.

 References:
https://github.com/remarshal-project/remarshal/releases/tag/v0.17.1
https://github.com/remarshal-project/remarshal/commit/fd6ac799a02f533c3fc243b49cdd6d21aa7ee494
https://jvn.jp/en/jp/JVN86156389/

Copyright 2026, cxsecurity.com

 

Back to Top