Skip to content

chore(deps): update module gopkg.in/yaml.v2 to v2.2.8 [security] (release-3.1) - #142

Open
jaydip-gk-renovate-test[bot] wants to merge 1 commit into
release-3.1from
renovate/release-3.1-go-gopkg.in-yaml.v2-vulnerability
Open

chore(deps): update module gopkg.in/yaml.v2 to v2.2.8 [security] (release-3.1)#142
jaydip-gk-renovate-test[bot] wants to merge 1 commit into
release-3.1from
renovate/release-3.1-go-gopkg.in-yaml.v2-vulnerability

Conversation

@jaydip-gk-renovate-test

Copy link
Copy Markdown

This PR contains the following updates:

Package Type Update Change
gopkg.in/yaml.v2 require patch v2.2.4v2.2.8
gopkg.in/yaml.v2 require patch v2.2.2v2.2.8

Excessive Platform Resource Consumption within a Loop in Kubernetes

CVE-2019-11254 / GHSA-wxc4-f4m6-wwqv / GO-2020-0036

More information

Details

The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.

Severity

  • CVSS Score: 6.5 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Excessive resource consumption in YAML parsing in gopkg.in/yaml.v2

CVE-2019-11254 / GHSA-wxc4-f4m6-wwqv / GO-2020-0036

More information

Details

Due to unbounded aliasing, a crafted YAML file can cause consumption of significant system resources. If parsing user supplied input, this may be used as a denial of service vector.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


YAML Go package vulnerable to denial of service

CVE-2021-4235 / GHSA-r88r-gmrh-7j83 / GO-2021-0061

More information

Details

Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.

Severity

  • CVSS Score: 5.5 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Denial of service in gopkg.in/yaml.v2

CVE-2021-4235 / GHSA-r88r-gmrh-7j83 / GO-2021-0061

More information

Details

Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


yaml package for Go can consume excessive amounts of CPU or memory

CVE-2022-3064 / GHSA-6q6q-88xp-6f2r / GO-2022-0956

More information

Details

Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Excessive resource consumption in gopkg.in/yaml.v2

CVE-2022-3064 / GHSA-6q6q-88xp-6f2r / GO-2022-0956

More information

Details

Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Release Notes

go-yaml/yaml (gopkg.in/yaml.v2)

v2.2.8

Compare Source

v2.2.7

Compare Source

v2.2.6

Compare Source

v2.2.5

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@jaydip-gk-renovate-test

Copy link
Copy Markdown
Author

ℹ️ Artifact update notice

File name: vendor/github.com/go-openapi/validate/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated

Details:

Package Change
github.com/stretchr/testify v1.4.0 -> v1.4.0

@jaydip-gk-renovate-test
jaydip-gk-renovate-test Bot force-pushed the renovate/release-3.1-go-gopkg.in-yaml.v2-vulnerability branch from 054b36d to 0375d56 Compare September 7, 2026 14:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants