CVE-2023-47163 is a high-severity denial-of-service (DoS) vulnerability affecting the Remarshal project's remarshal prior to version 0.17.1. This flaw, categorized as a Billion Laughs Attack (CWE-674), allows an unauthenticated attacker to cause a DoS by processing specially crafted, untrusted YAML files due to unlimited expansion of YAML alias nodes. While the CVSS score is 7.5 (HIGH), indicating a significant impact on availability, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.17.1CPE matchmatch criteria | cpe:2.3:a:remarshal_project:remarshal:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.