THREAT OPS › Threat News › [GHSA] GHSA-q6hh-gp44-4hcm (medium) — Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
[GHSA] GHSA-q6hh-gp44-4hcm (medium) — Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
GHSA-q6hh-gp44-4hcm Severity: medium CVE: CVE-2026-52857
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
### Summary Config file parsers, `json`, `yaml`, `xml` etc in parser.go have no file size limit/checks, allowing for a giant config file to potentially OOM the wings process.
### Impact All wings users who have an egg with a non-`file` parser conf
Indicators of compromise
- CVE-2026-52857cve
Original source: https://github.com/advisories/GHSA-q6hh-gp44-4hcm