{"id":"CVE-2022-25857","aliases":["GHSA-3mc7-4q67-w48m"],"url":"https://o3.security/vulnerability/CVE-2022-25857","summary":"Denial of Service (DoS)","details":"The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.","published":"2022-08-30T05:05:11.588Z","modified":"2026-08-12T13:00:30.061712Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Maven","name":"org.yaml:snakeyaml","fixedVersion":"1.31"}],"fix":{"url":"https://github.com/snakeyaml/snakeyaml/commit/fc300780da21f4bb92c148bc90257201220cf174","label":"snakeyaml/snakeyaml@fc30078"},"references":[{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGYAML-2806360"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/25xxx/CVE-2022-25857.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-25857"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240315-0010/"},{"type":"REPORT","url":"https://bitbucket.org/snakeyaml/snakeyaml/issues/525"},{"type":"FIX","url":"https://bitbucket.org/snakeyaml/snakeyaml/commits/fc300780da21f4bb92c148bc90257201220cf174"},{"type":"FIX","url":"https://github.com/snakeyaml/snakeyaml/commit/fc300780da21f4bb92c148bc90257201220cf174"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2022/10/msg00001.html"},{"type":"PACKAGE","url":"https://github.com/snakeyaml/snakeyaml"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20240315-0010"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T13:00:30.061712Z"}}