This package has limited bug data (2 entries). Check back later or see the package health page for the full signal.

serde_yaml known bugs

cargo

2 known bugs in serde_yaml, with affected versions, fixes and workarounds. Sourced from upstream issue trackers.

2
bugs
Known bugs
SeverityAffectedFixed inTitleStatusSource
medium0.6.0-rc10.8.4
Uncontrolled recursion leads to abort in deserialization
Affected versions of this crate did not properly check for recursion while deserializing aliases. This allows an attacker to make a YAML file with an alias referring to itself causing an abort. The flaw was corrected by checking the recursion depth.
fixedosv:RUSTSEC-2018-0005
medium0.6.0-rc10.8.4
Uncontrolled recursion leads to abort in deserialization
Affected versions of this crate did not properly check for recursion while deserializing aliases. This allows an attacker to make a YAML file with an alias referring to itself causing an abort. The flaw was corrected by checking the recursion depth.
fixedosv:GHSA-39vw-qp34-rmwf
API access

Get this data programmatically \u2014 free, no authentication.

curl https://depscope.dev/api/bugs/cargo/serde_yaml
serde_yaml bugs — known issues per version | DepScope | DepScope