Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Security Vulnerability: gopkg.in/yaml.v3 #154

Open
sanjayjohn opened this issue Aug 10, 2022 · 0 comments
Open

Security Vulnerability: gopkg.in/yaml.v3 #154

sanjayjohn opened this issue Aug 10, 2022 · 0 comments

Comments

@sanjayjohn
Copy link

gopkg.in/yaml.v3 is a YAML support package for the Go language.

Affected versions of this package are vulnerable to NULL Pointer Dereference when parsing #\n-\n-\n0 via the parserc.go parser.

v0.10.0 is still on an outdated version: https://github.com/slok/go-http-metrics/blob/v0.10.0/go.mod#L59

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant