remarshal-project/remarshal

remarshal-project/remarshal

Releases37
Frequency3 months 3 weeks
Last Release
Stars549
Convert between CBOR, JSON, MessagePack, TOML, and YAML 1.1 & 1.2

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

Remarshal prior to v0.17.1 expands YAML alias nodes unlimitedly, hence Remarshal is vulnerable to Billion Laughs Attack. Processing untrusted YAML files may cause a denial-of-service (DoS) condition.