THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-q6hh-gp44-4hcm (medium) — Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM

[GHSA] GHSA-q6hh-gp44-4hcm (medium) — Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM

medgithub_advisoriesPublished 2026-07-31

GHSA-q6hh-gp44-4hcm Severity: medium CVE: CVE-2026-52857

Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM

### Summary Config file parsers, `json`, `yaml`, `xml` etc in parser.go have no file size limit/checks, allowing for a giant config file to potentially OOM the wings process.

### Impact All wings users who have an egg with a non-`file` parser conf

Indicators of compromise

Original source: https://github.com/advisories/GHSA-q6hh-gp44-4hcm