Compose-Go Library Denial-of-Service Vulnerability
Vulnerability
A denial-of-service vulnerability has been identified in the Compose-Go library, specifically in versions 2.10 through 2.4.0. This vulnerability allows an authorized user to send malicious YAML payloads that cause the library to excessively consume memory and CPU resources while parsing the YAML. This issue affects Docker Compose versions 2.27.0 to 2.29.7.
Impact
Exploitation of this vulnerability leads to a significant denial-of-service condition, causing high resource consumption that can disrupt normal operations.
Remediation
Users can upgrade to Compose-Go version 2.4.1, which addresses this vulnerability.
Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
5.2remediation
7.7relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
