Vulnerability in codex project

Resolved 💬 1 comment Opened Mar 26, 2026 by ankitdn Closed Mar 26, 2026

What is the type of issue?

_No response_

What is the issue?

While working on codex project, I scanned the dependency manifest and found that it uses a vulnerable version of yaml. The scan revealed a stack overflow issue where deeply nested YAML collections can trigger a “Maximum call stack size exceeded” error, potentially causing the application to crash when processing untrusted input.

CVE Report
CVE Link

Where did you find it?

_No response_

View original on GitHub ↗

This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗