CVE-2024-10846

The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to cause the compose-go to consume excessive amount of Memory and CPU cycles while parsing YAML, such as used by Docker Compose from versions v2.27.0 to v2.29.7 included
Configurations

No configuration.

History

No history.

Information

Published : 2025-01-23 16:15

Updated : 2025-04-25 23:15


NVD link : CVE-2024-10846

Mitre link : CVE-2024-10846

CVE.ORG link : CVE-2024-10846


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation