CVE-2022-41854EPSS p70.5%

CVE-2022-41854CVE-2022-41854

snakeyaml_project / snakeyaml

Description

Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack.

Scoring

CVSS 5.8 ()
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H
EPSS1.48% probability of exploitation · percentile 70.5% · 2026-06-19T12:03:05Z
Last modified2026-06-17
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.