Remarshal prior to v0.17.1 expands YAML alias nodes unlimitedly, hence Remarshal is vulnerable to Billion Laughs Attack. Processing untrusted YAML files may cause a denial-of-service (DoS) condition.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| remarshal(PyPI) | 0 | 0.17.1 | N/A |
CVSS Metrics