CVE-2023-28118 - CVE House
Back to Database
Status published High CVE-2023-28118

kaml has potential denial of service while parsing input with anchors and aliases

Vulnerability Description

kaml provides YAML support for kotlinx.serialization. Prior to version 0.53.0, applications that use kaml to parse untrusted input containing anchors and aliases may consume excessive memory and crash. Version 0.53.0 and later default to refusing to parse YAML documents containing anchors and aliases. There are no known workarounds.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-28118

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

charleskorn

View all reports →

Affected Software

kaml
Vulnerable Versions:
< 0.53.0

Timeline

Official Publish: March 20th, 2023
Last Modified: February 25th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.