Denial of Service Vulnerability in Docker Compose by Compose-Go Library
CVE-2024-10846
5.9MEDIUM
What is CVE-2024-10846?
The compose-go library, utilized in various versions of Docker Compose, is susceptible to denial of service attacks. An authorized user can exploit this vulnerability by sending specially crafted YAML payloads. This can lead to excessive consumption of memory and CPU resources during the YAML parsing process, resulting in service disruptions and impacting the performance of the affected Docker Compose instances.
Affected Version(s)
compose-go 0 <= 2.4.0
