Compose-Go Library Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the Compose-Go library, specifically in versions 2.10 through 2.4.0. This vulnerability allows an authorized user to send malicious YAML payloads that cause the library to excessively consume memory and CPU resources while parsing the YAML. This issue affects Docker Compose versions 2.27.0 to 2.29.7.

Impact

Exploitation of this vulnerability leads to a significant denial-of-service condition, causing high resource consumption that can disrupt normal operations.

Remediation

Users can upgrade to Compose-Go version 2.4.1, which addresses this vulnerability.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.