Vulnerability Report: GO-2025-3412
- CVE-2024-10846, GHSA-36gq-35j3-p9r9
- Affects: github.com/compose-spec/compose-go/v2
- Published: Jan 29, 2025
Excessive resource consumption when unmarshalling Compose file with recursive loop in github.com/compose-spec/compose-go/v2
For detailed information about this vulnerability, visit https://github.com/compose-spec/compose-go/security/advisories/GHSA-36gq-35j3-p9r9.
Affected Modules
-
PathGo Versions
-
from v2.1.0 before v2.4.1
Aliases
References
- https://github.com/compose-spec/compose-go/security/advisories/GHSA-36gq-35j3-p9r9
- https://github.com/compose-spec/compose-go/pull/618
- https://github.com/compose-spec/compose-go/pull/703
- https://github.com/docker/compose/commit/d239f0f3187a2ed5404c61f83bd5e995c81600ff
- https://github.com/docker/compose/issues/12235
- https://vuln.go.dev/ID/GO-2025-3412.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.