FlawAtlas
Search the atlas
CVE-2022-28948 High

CVE-2022-28948

An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.

Exploit probability 4.0%
Published May 19, 2022
Required by Not available
Last source change August 12, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

2 explicit affected versions

Go gopkg.in/yaml.v3
Go gopkg.in/yaml.v3

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2022-28948

An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.

View original source
Open Source Vulnerabilities GHSA-hp87-p4gw-j4gq

An issue in the Unmarshal function in Go-Yaml v3 can cause a program to panic when attempting to deserialize invalid input.

View original source
Open Source Vulnerabilities GO-2022-0603

An issue in the Unmarshal function can cause a program to panic when attempting to deserialize invalid input.

View original source

05 / REFERENCES

Further evidence