serde_yaml_bw is vulnerable to Allocation of Resources Without Limits or Throttling
20
Low Risk
serde_yaml_bw did not consider limitation in processing long sequences of user-crafted YAML files. While this does not directly lead to a crash, it may consume excessive memory to process this input. This has the potential of a denial-of-service attack if multiple large sequences are processed at the same time.
You are affected if you are using a version that falls within the vulnerable range.
serde_yaml_bw is vulnerable to Allocation of Resources Without Limits or Throttling in versions 1.0.0 - 2.3.0.
Upgrade to the patch version of serde_yaml_bw.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant