Skip to content

Conversation

@00felix-app
Copy link

@00felix-app 00felix-app bot commented Aug 6, 2025

Upgrade org.yaml:snakeyaml from 1.21 to 2.0

This pull request upgrades org.yaml:snakeyaml from version 1.21 to 2.0 to address multiple security vulnerabilities and ensure compliance with security best practices. The upgrade has been tested locally to confirm compatibility with existing functionality.
Vulnerabilities Addressed

Vulnerability Description
CVE-2017-18640 SnakeYAML Entity Expansion during load operation. SnakeYAML Entity Expansion during load operation

| CVE-2022-38749 | snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write. snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write |

| CVE-2022-25857 | Uncontrolled Resource Consumption in snakeyaml. Uncontrolled Resource Consumption in snakeyaml |

| CVE-2022-38751 | snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write. snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write |

| CVE-2022-38750 | snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write. snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write |

| CVE-2022-38752 | snakeYAML before 1.32 vulnerable to Denial of Service due to Out-of-bounds Write. snakeYAML before 1.32 vulnerable to Denial of Service due to Out-of-bounds Write |

| CVE-2022-41854 | Snakeyaml vulnerable to Stack overflow leading to denial of service. Snakeyaml vulnerable to Stack overflow leading to denial of service |

| CVE-2022-1471 | SnakeYaml Constructor Deserialization Remote Code Execution. SnakeYaml Constructor Deserialization Remote Code Execution |

This upgrade enhances the security and stability of the org.yaml:snakeyaml dependency.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant