CVE-2021-39194 is a denial-of-service vulnerability affecting the kaml library, an open-source YAML implementation for Kotlin. Attackers providing specially crafted YAML input to applications using kaml with default tagged polymorphic serialization could trigger an infinite loop, leading to resource exhaustion and application unavailability. This medium-severity vulnerability (CVSS 6.5) requires low privileges and network access, with a high impact on availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.35.3CPE matchmatch criteria | cpe:2.3:a:kaml_project:kaml:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.