{"id":"CVE-2019-11254","aliases":["GHSA-wxc4-f4m6-wwqv","GO-2020-0036"],"url":"https://o3.security/vulnerability/CVE-2019-11254","summary":"Excessive Platform Resource Consumption within a Loop in Kubernetes","details":"The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.","published":"2020-04-01T21:15:13.397Z","modified":"2026-08-07T14:48:30.246130Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"gopkg.in/yaml.v2","fixedVersion":"2.2.8"},{"ecosystem":"Go","name":"github.com/go-yaml/yaml","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/kubernetes/kubernetes/issues/89535"},{"type":"ADVISORY","url":"https://groups.google.com/d/msg/kubernetes-announce/ALL9s73E5ck/4yHe8J-PBAAJ"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20200413-0003/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:48:30.246130Z"}}