Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Yaml | Yaml_project | * | 2.2.3 (excluding) | 
| Red Hat OpenShift Container Platform 4.12 | RedHat | openshift-clients-0:4.12.0-202301042257.p0.g854f807.assembly.stream.el8 | * | 
| Red Hat OpenShift Container Platform 4.12 | RedHat | openshift4/ose-installer:v4.12.0-202301271115.p0.g7fea1c4.assembly.stream | * | 
| Red Hat OpenShift Container Platform 4.12 | RedHat | openshift4/metallb-rhel8-operator:v4.12.0-202301301729.p0.g917cd33.assembly.stream | * | 
| Red Hat OpenShift Container Platform 4.12 | RedHat | openshift4/ose-openshift-controller-manager-rhel8:v4.12.0-202306090942.p0.gb6528f9.assembly.stream | * | 
| Red Hat OpenShift Container Platform 4.13 | RedHat | openshift4/ose-installer:v4.13.0-202305091542.p0.g44db7b2.assembly.stream | * | 
| Red Hat OpenShift Container Platform 4.13 | RedHat | openshift4/ose-machine-api-operator:v4.13.0-202304190216.p0.ga23baf7.assembly.stream | * | 
| RHODF-4.13-RHEL-9 | RedHat | odf4/mcg-rhel9-operator:v4.13.0-41 | * | 
| RHODF-4.13-RHEL-9 | RedHat | odf4/odf-rhel9-operator:v4.13.0-24 | * | 
| Golang-github-coreos-discovery-etcd-io | Ubuntu | devel | * | 
| Golang-github-coreos-discovery-etcd-io | Ubuntu | esm-apps/focal | * | 
| Golang-github-coreos-discovery-etcd-io | Ubuntu | esm-apps/jammy | * | 
| Golang-github-coreos-discovery-etcd-io | Ubuntu | esm-apps/noble | * | 
| Golang-github-coreos-discovery-etcd-io | Ubuntu | focal | * | 
| Golang-github-coreos-discovery-etcd-io | Ubuntu | jammy | * | 
| Golang-github-coreos-discovery-etcd-io | Ubuntu | kinetic | * | 
| Golang-github-coreos-discovery-etcd-io | Ubuntu | lunar | * | 
| Golang-github-coreos-discovery-etcd-io | Ubuntu | mantic | * | 
| Golang-github-coreos-discovery-etcd-io | Ubuntu | noble | * | 
| Golang-github-coreos-discovery-etcd-io | Ubuntu | oracular | * | 
| Golang-github-coreos-discovery-etcd-io | Ubuntu | plucky | * | 
| Golang-github-coreos-discovery-etcd-io | Ubuntu | questing | * | 
| Golang-github-coreos-discovery-etcd-io | Ubuntu | trusty | * | 
| Golang-github-coreos-discovery-etcd-io | Ubuntu | xenial | * | 
| Golang-gopkg-yaml.v3 | Ubuntu | kinetic | * | 
| Golang-gopkg-yaml.v3 | Ubuntu | trusty | * | 
| Golang-gopkg-yaml.v3 | Ubuntu | xenial | * | 
| Golang-yaml.v2 | Ubuntu | bionic | * | 
| Golang-yaml.v2 | Ubuntu | esm-apps/bionic | * | 
| Golang-yaml.v2 | Ubuntu | esm-apps/focal | * | 
| Golang-yaml.v2 | Ubuntu | esm-infra/xenial | * | 
| Golang-yaml.v2 | Ubuntu | focal | * | 
| Golang-yaml.v2 | Ubuntu | kinetic | * | 
| Golang-yaml.v2 | Ubuntu | trusty | * | 
| Golang-yaml.v2 | Ubuntu | upstream | * | 
| Golang-yaml.v2 | Ubuntu | xenial | * | 
| Kubernetes | Ubuntu | focal | * | 
| Kubernetes | Ubuntu | kinetic | * | 
| Kubernetes | Ubuntu | lunar | * | 
| Kubernetes | Ubuntu | mantic | * | 
| Kubernetes | Ubuntu | oracular | * | 
| Kubernetes | Ubuntu | trusty | * | 
| Kubernetes | Ubuntu | xenial | * | 
| Singularity-container | Ubuntu | bionic | * | 
| Singularity-container | Ubuntu | oracular | * | 
| Singularity-container | Ubuntu | trusty | * | 
| Singularity-container | Ubuntu | xenial | * | 
| Webhook | Ubuntu | bionic | * | 
| Webhook | Ubuntu | focal | * | 
| Webhook | Ubuntu | kinetic | * | 
| Webhook | Ubuntu | lunar | * | 
| Webhook | Ubuntu | mantic | * | 
| Webhook | Ubuntu | oracular | * | 
| Webhook | Ubuntu | trusty | * | 
| Webhook | Ubuntu | xenial | * |