#VU82999 XML Entity Expansion in kaml - CVE-2023-28118
Published: November 13, 2023
kaml
charleskorn
Description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to applications that use kaml to parse untrusted input containing anchors and aliases may consume excessive memory and crash. A remote unauthenticated attacker can pass specially crafted XML data to the application and perform a denial of service attack.