Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-0125 | Excessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loop |
Github GHSA |
GHSA-36gq-35j3-p9r9 | Excessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loop |
Fri, 25 Apr 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 12 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Jan 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to cause the compose-go to consume excessive amount of Memory and CPU cycles while parsing YAML, such as used by Docker Compose from versions v2.27.0 to v2.29.7 included | |
| Title | Excessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loop | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2025-04-25T23:02:53.505Z
Reserved: 2024-11-05T10:21:55.528Z
Link: CVE-2024-10846
Updated: 2025-04-25T23:02:53.505Z
Status : Deferred
Published: 2025-01-23T16:15:33.533
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-10846
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA