CVE-2022-28948
High
CVE-2022-28948
An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.
Exploit probability
4.0%
Published
May 19, 2022
Required by
Not available
Last source change
August 12, 2026
02 / AFFECTED SOFTWARE
Affected packages
2 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2022-28948
View original source
An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.
Open Source Vulnerabilities
GHSA-hp87-p4gw-j4gq
View original source
An issue in the Unmarshal function in Go-Yaml v3 can cause a program to panic when attempting to deserialize invalid input.
Open Source Vulnerabilities
GO-2022-0603
View original source
An issue in the Unmarshal function can cause a program to panic when attempting to deserialize invalid input.
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/28xxx/CVE-2022-28948.json
- https://github.com/go-yaml/yaml/issues/666
- https://nvd.nist.gov/vuln/detail/CVE-2022-28948
- https://security.netapp.com/advisory/ntap-20220923-0006/
- https://github.com/go-yaml/yaml
- https://github.com/go-yaml/yaml/commit/8f96da9f5d5eff988554c1aae1784627c4bf6754
- https://github.com/go-yaml/yaml/commit/f6f7691b1fdeb513f56608cd2c32c51f8194bf51
- https://github.com/go-yaml/yaml/issues/665
- https://security.netapp.com/advisory/ntap-20220923-0006