Kaml Kamlproject Kaml

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Kamlproject Kaml.

By the Year

In 2026 there have been 0 vulnerabilities in Kamlproject Kaml. Kaml did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 0 0.00
2023 1 7.50
2022 0 0.00
2021 1 6.50

It may take a day or so for new Kaml vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Kamlproject Kaml Security Vulnerabilities

kaml <0.53.0 YAML Anchors Memory Attack
CVE-2023-28118 7.5 - High - March 20, 2023

kaml provides YAML support for kotlinx.serialization. Prior to version 0.53.0, applications that use kaml to parse untrusted input containing anchors and aliases may consume excessive memory and crash. Version 0.53.0 and later default to refusing to parse YAML documents containing anchors and aliases. There are no known workarounds.

XEE

kaml is an open source implementation of the YAML format with support for kotlinx.serialization
CVE-2021-39194 6.5 - Medium - September 07, 2021

kaml is an open source implementation of the YAML format with support for kotlinx.serialization. In affected versions attackers that could provide arbitrary YAML input to an application that uses kaml could cause the application to endlessly loop while parsing the input. This could result in resource starvation and denial of service. This only affects applications that use polymorphic serialization with the default tagged polymorphism style. Applications using the property polymorphism style are not affected. YAML input for a polymorphic type that provided a tag but no value for the object would trigger the issue. Version 0.35.3 or later contain the fix for this issue.

Infinite Loop

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Kamlproject Kaml or by Kamlproject? Click the Watch button to subscribe.

Kamlproject
Vendor

subscribe