GHSA-36gq-35j3-p9r9 · Severity: medium · Ecosystem: go — Excessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loop
The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to cause the compose-go to consume excessive amount of Memory and CPU cycles while parsing YAML, such as used by Docker Compose from versions v2.27.0 to v2.29.7 included
Conclusion & alert: CVE-2024-10846 is rated Low Risk (25.6/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.02%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-08 | 0.07% | 0.02% | -0.05% |
| 2 | 2026-03-01 | 0.03% | 0.07% | +0.04% |
| 3 | 2025-11-21 | — | 0.03% | — |
Full EPSS history (5 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.9 | 3.1 | MEDIUM |
|
1.5 | 4.0 | [email protected] |
GHSA-36gq-35j3-p9r9 · Severity: medium · Ecosystem: go — Excessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loop
| vendor | priority | summary | link |
|---|---|---|---|
suse
|
medium | CVE-2024-10846 severity moderate: SUSE including 18 source package names (docker, docker-bash-completion, …), 164 product×package rows across 55 product lines (Container suse/sl-micro/6.0/baremetal-os-container, Container suse/sl-micro/6.0/base-os-container, … (55 product lines)): Known Not Affected 113, Fixed 51. | https://www.suse.com/security/cve/CVE-2024-10846/ |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||