An issue was discovered in singledocparser.cpp in yaml-cpp (aka LibYaml-C++) 0.6.2. Stack Exhaustion occurs in YAML::SingleDocParser, and there is a stack consumption problem caused by recursive stack frames: HandleCompactMap, HandleMap, HandleFlowSequence, HandleSequence, HandleNode. Remote attackers could leverage this vulnerability to cause a denial-of-service via a cpp file.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-yaml-cpp | Jul 30, 2024 | Jan 15, 2019 | |
| Dell Powerstore Dsa2023366 | dell-powerstoreos-upgrade-latest | Jan 13, 2026 | Oct 5, 2023 | |
| Suse | — | suse-upgrade-libyaml-cpp0_5suse-upgrade-libyaml-cpp0_6suse-upgrade-yaml-cpp-devel | Aug 9, 2024 | Jan 15, 2019 |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Jan 15, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub