CVE-2024-10846

The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to cause the compose-go to consume excessive amount of Memory and CPU cycles while parsing YAML, such as used by Docker Compose from versions v2.27.0 to v2.29.7 included
Configurations

No configuration.

History

25 Apr 2025, 23:15

Type Values Removed Values Added
Summary
  • (es) El componente compose-go library en las versiones v2.10-v2.4.0 permite que un usuario autorizado que envíe YAML payloads maliciosos haga que compose-go consuma una cantidad excesiva de memoria y ciclos de CPU mientras analiza YAML, como lo usa Docker Compose desde las versiones v2.27.0 a v2.29.7 incluidas.
References
  • () https://security.netapp.com/advisory/ntap-20250425-0008/ -

23 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-23 16:15

Updated : 2025-04-25 23:15


NVD link : CVE-2024-10846

Mitre link : CVE-2024-10846

CVE.ORG link : CVE-2024-10846


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation