Infinite loop in kaml - CVE-2021-39194

 

Infinite loop in kaml - CVE-2021-39194

Published: February 18, 2026


Vulnerability identifier: #VU123005
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-39194
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop. A remote user can provide arbitrary YAML input to an application that uses kaml to cause the application to endlessly loop while parsing the input leading to resource starvation and denial of service.


Affected software

kaml
IBM Operator for Apache Flink

How to mitigate CVE-2021-39194

Install updates from vendor's website.

kaml - update to 0.35.3
IBM Operator for Apache Flink - update to 1.4.5

External References

Related Security Bulletins