Denial of Service Vulnerability in Docker Compose by Compose-Go Library
CVE-2024-10846

5.9MEDIUM

Key Information:

Vendor
CVE Published:
23 January 2025

What is CVE-2024-10846?

The compose-go library, utilized in various versions of Docker Compose, is susceptible to denial of service attacks. An authorized user can exploit this vulnerability by sending specially crafted YAML payloads. This can lead to excessive consumption of memory and CPU resources during the YAML parsing process, resulting in service disruptions and impacting the performance of the affected Docker Compose instances.

Affected Version(s)

compose-go 0 <= 2.4.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.