CVE-2022-3064High· 7.5▾ TwilightA flaw was found in go-yaml. This issue causes the consumption of excessive amounts of CPU or memory when attempting to parse a large or maliciously crafted YAML document.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
1.7%
Last analysed / modified upstream
A flaw was found in go-yaml. This issue causes the consumption of excessive amounts of CPU or memory when attempting to parse a large or maliciously crafted YAML document.
go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents — rated Important by Red Hat. Released 2022-08-29, updated 2026-09-19.
Affected:
Fixed:
No fix planned:
Not affected:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:0804 For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:0802 For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:0803
Affected packages:
gopkg.in/yaml.v2 < 2.2.4Patched in:
gopkg.in/yaml.v2 2.2.4Connected by shared product, vendor, weakness, or advisory.
CVE-2022-23524High· 7.5helm: Denial of service through string value parsing (CVE-2022-23524)
CVE-2024-1313Medium· 6.5grafana: vulnerable to authorization bypass (CVE-2024-1313)
CVE-2023-25153Medium· 5.5containerd: OCI image importer memory exhaustion (CVE-2023-25153)
CVE-2026-42501Medium· 5.3cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy (CVE-2026-42501)
CVE-2026-39817Medium· 5.9cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction (CVE-2026-39817)
CVE-2026-39819Medium· 4.4cmd/go: golang: Go 'go bug' command: Arbitrary file overwrite via symlink attack (CVE-2026-39819)