CVE-2026-33320

EUVD-2026-20094
Dasel is a command-line tool and library for querying, modifying, and transforming data structures. Starting in version 3.0.0 and prior to version 3.3.1, Dasel's YAML reader allows an attacker who can supply YAML for processing to trigger extreme CPU and memory consumption. The issue is in the library's own `UnmarshalYAML` implementation, which manually resolves alias nodes by recursively following `yaml.Node.Alias` pointers without any expansion budget, bypassing go-yaml v4's built-in alias expansion limit. Version 3.3.2 contains a patch for the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.2 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 11.39%
Affected Products (NVD)
VendorProductVersion
tomwrightdasel
3.0.0 ≤
𝑥
< 3.3.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dasel
forky
3.11.2-1
fixed
sid
3.11.2-2
fixed
trixie
2.8.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dasel
jammy
dne
noble
needs-triage
questing
ignored
resolute
needs-triage