{"id":"CVE-2023-28118","aliases":["GHSA-c24f-2j3g-rg48"],"url":"https://o3.security/vulnerability/CVE-2023-28118","summary":"kaml has potential denial of service while parsing input with anchors and aliases ","details":"### Impact\nApplications that use kaml to parse untrusted input containing anchors and aliases may consume excessive memory and crash.\n\n### Patches\nVersion 0.53.0 and later default to refusing to parse YAML documents containing anchors and aliases.\n\n### Workarounds\nNone.\n\n### References\nWikipedia has an explanation of this class of vulnerability: [billion laughs attack](https://en.wikipedia.org/wiki/Billion_laughs_attack)\n\n### Acknowledgements\nThank you to @gdude2002 for reporting this issue.","published":"2023-03-20T12:39:42.075Z","modified":"2026-08-12T03:51:10.590983948Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.charleskorn.kaml:kaml","fixedVersion":"0.53.0"}],"fix":{"url":"https://github.com/charleskorn/kaml/commit/5f82a2d7e00bfc307afca05d1dc4d7c50593531a","label":"charleskorn/kaml@5f82a2d"},"references":[{"type":"WEB","url":"https://github.com/charleskorn/kaml/releases/tag/0.53.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/28xxx/CVE-2023-28118.json"},{"type":"ADVISORY","url":"https://github.com/charleskorn/kaml/security/advisories/GHSA-c24f-2j3g-rg48"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-28118"},{"type":"FIX","url":"https://github.com/charleskorn/kaml/commit/5f82a2d7e00bfc307afca05d1dc4d7c50593531a"},{"type":"PACKAGE","url":"https://github.com/charleskorn/kaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:10.590983948Z"}}