Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 PyPI

Remarshal expands YAML alias nodes unlimitedly, hence Remarshal is vulnerable to Billion Laughs Attack

GHSA-gw7g-qr8w-3448 · CVE-2023-47163 · PYSEC-2023-236

Published · Modified

Description

Remarshal prior to v0.17.1 expands YAML alias nodes unlimitedly, hence Remarshal is vulnerable to Billion Laughs Attack. Processing untrusted YAML files may cause a denial-of-service (DoS) condition.

Ready to move

Start Securing

Free, no credit card | First findings in minutes