Related Vulnerabilities: CVE-2022-28948  

A flaw was found in the Unmarshal function in Go-Yaml. The issue causes the program to crash when attempting to deserialize invalid input.

Description

A flaw was found in the Unmarshal function in Go-Yaml. The issue causes the program to crash when attempting to deserialize invalid input.

Additional Information

  • Bugzilla 2088748: CVE-2022-28948 golang-gopkg-yaml: crash when attempting to deserialize invalid input
  • CWE-502: Deserialization of Untrusted Data
  • FAQ: Frequently asked questions about CVE-2022-28948