🔐 CVE Alert

CVE-2026-27807

MEDIUM 4.9

MarkUs: YAML alias (‘billion laughs’) DoS in config upload

CVSS Score
4.9
EPSS Score
0.0%
EPSS Percentile
0th

MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs allows course instructors to upload YAML files to create/update various entities (e.g., assignment settings). These YAML files are parsed with aliases enabled. This issue has been patched in version 2.9.4.

CWE CWE-776
Vendor markusproject
Product markus
Published Mar 6, 2026
Last Updated Mar 6, 2026
Stay Ahead of the Next One

Get instant alerts for markusproject markus

Be the first to know when new medium vulnerabilities affecting markusproject markus are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

MarkUsProject / Markus
< 2.9.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/MarkUsProject/Markus/security/advisories/GHSA-m9rx-85mx-q9h6 github.com: https://github.com/MarkUsProject/Markus/releases/tag/v2.9.4