<oai_dc:dc xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:oai_dc="http://www.openarchives.org/OAI/2.0/oai_dc/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/oai_dc/ http://www.openarchives.org/OAI/2.0/oai_dc.xsd">
  
    
  <dc:creator>Benjamin Oberdorfer</dc:creator>
    
  
    
  <dc:description xml:lang="deu">Das benutzerfreundliche Datenserialisierungsformat YAML Ain&#39;t Markup Language (YAML) wird unter anderem in Cloud-Infrastrukturen, der Maschine-zu-Maschine-Kommunikation und Konfigurationsdateien häufig verwendet. Die Homogenität von YAML-Parser-Bibliotheken ist von essenzieller Bedeutung für die Gewährleistung von Sicherheit, Zuverlässigkeit und Interoperabilität. Die YAML 1.2.2 Spezifikation ist jedoch komplex, sodass eine vollständige Konformität schwer zu erreichen ist.

Um festzustellen, ob sich YAML 1.2-Parser-Bibliotheken voneinander unterscheiden, wurde eine YAML Test Suite entwickelt. Die YAML Test Suite umfasst 16 YAML 1.2 Parser-Bibliotheken und 245 YAML Testfalldateien, die durch Lesen der YAML 1.2.2 Spezifikation erstellt wurden. Die Ergebnisse werden dann automatisch ausgewertet, um festzustellen, ob die YAML Parser-Bibliotheken eine Datei korrekt parsen oder nicht. Zusätzlich werden Timeouts und Abstürze verfolgt.

Die Ergebnisse der YAML-Testsuite zeigen, dass zwar alle Parsing-Bibliotheken mehr als 50% der YAML Testfalldateien korrekt parsen können, aber keine YAML-Parsing-Bibliothek vollständig mit der YAML 1.2.2 Spezifikation kompatibel ist. Manchmal werden gültige YAML Testfalldateien abgelehnt, und in anderen Fällen werden ungültige YAML Testfalldateien akzeptiert. Es wurde auch festgestellt, dass YAML Parser-Bibliotheken bestimmte Funktionen, die in der YAML 1.2.2 Spezifikation festgelegt sind, einheitlich ignorieren. Ferner liefern keine zwei YAML Parser-Bibliotheken die gleichen Ergebnisse, wenn sie mit dem gleichen Satz von YAML Testfalldateien versorgt werden.

Außerdem wurden potenzielle Denial-of-Service-Schwachstellen (DoS) gefunden. Es wurde festgestellt, dass 14 von 16 YAML Parser-Bibliotheken während der Ausführung der YAML Test Suite mindestens einmal einen Timeout verursachen. Die Bibliotheken _HsYAML_ und _YamlReference_ wurden weiter analysiert und es wurde festgestellt, dass sie während dem Parsing einer YAML Testfalldatei, die eine immense Menge an Verschachtelungen enthält, einen nicht linearen Anstieg der Ausführungszeit aufweisen. Des Weiteren verursachen die YAML Parser-Bibliotheken _yaml-rust_ und _YamlDotNet_ einen Stapelüberlauf-Fehler. Obwohl beide Bibliotheken bei unterschiedlichen YAML Testfalldateien abstürzen, ist das zugrunde liegende Problem dasselbe. Bei einer tief verschachtelten Sequenz tritt ein Stapelüberlauf-Fehler auf. Anwendungen, die diese Bibliotheken zum Parsen von benutzerdefinierten YAML-Eingaben verwenden, können anfällig für DoS-Angriffe sein.

Zusammenfassend kann gesagt werden, dass die YAML 1.2.2 Spezifikation von den YAML Parser-Bibliotheken nur teilweise und uneinheitlich eingehalten wird. Dies untergräbt die Wirksamkeit der YAML 1.2.2 Spezifikation. Daher ist das Verhalten von YAML Parsing-Bibliotheken unvorhersehbar und inkompatibel, insbesondere weil keine zwei YAML Parsing-Bibliotheken identische Ergebnisse liefern.</dc:description>
    
  <dc:description xml:lang="deu">The user-friendly data serialization format known as YAML Ain&#39;t Markup Language (YAML) is widely used in cloud infrastructure, machine-to-machine communication, and configuration files, among other applications. Consistency among YAML parser libraries is essential for security, reliability, and interoperability. However, the YAML 1.2.2 specification is complex, making full compliance difficult to achieve.

To determine whether YAML 1.2 parser libraries differ from each other, a YAML Test Suite is developed. The YAML Test Suite includes 16 YAML 1.2 parser libraries and 245 YAML test case files that are created by reading the YAML 1.2.2 specification. The results are then automatically evaluated to determine whether the YAML parser libraries correctly parse a file or not. Additionally, timeouts and crashes are also tracked.

The results of the YAML Test Suite present that, while all parsing libraries can parse more than 50% of YAML test case files correctly, no YAML parsing library is completely compliant with the YAML 1.2.2 specification. Sometimes valid YAML test case files are rejected, and on other occasions invalid YAML test case files are accepted. It is also found that YAML parser libraries uniformly ignore certain features that are specified in the YAML 1.2.2 specification. In addition, no two YAML parser libraries produce the same results when supplied with the same set of YAML test case files.

In addition, potential Denial of Service (DoS) vulnerabilities are found. It is found that 14 out of 16 YAML parser libraries run into a timeout at least once during the run of the YAML Test Suite. The libraries _HsYAML_ and _YamlReference_ are further analyzed and are found to have a nonlinear increase in execution time during the parsing of a YAML test case file that contains an immense amount of nesting. Moreover, the YAML parser libraries _yaml-rust_ and _YamlDotNet_ produce a stack overflow error. While both libraries crash on different YAML test case files, the underlying issue is the same. When a sequence is deeply nested, a stack overflow error happens. Applications that use these libraries for parsing user-supplied YAML input can be susceptible to DoS attacks.

In conclusion, compliance with the YAML 1.2.2 specification is given only partially and inconsistently across YAML parser libraries. This undermines the effectiveness of the YAML 1.2.2 specification. Therefore, the behavior of YAML parsing libraries is unpredictable and incompatible, particularly because no two YAML parsing libraries generate identical results.</dc:description>
    
  <dc:description xml:lang="deu">Fachhochschule St. Pölten, Masterarbeit 2026, Studiengang Information Security</dc:description>
    
  
    
  <dc:subject xml:lang="deu">YAML</dc:subject>
    
  <dc:subject xml:lang="deu">Parser Konformität</dc:subject>
    
  <dc:subject xml:lang="deu">Robustheit</dc:subject>
    
  <dc:subject xml:lang="deu">Denial of Service</dc:subject>
    
  <dc:subject xml:lang="deu">differential testing</dc:subject>
    
  
    
  <dc:rights>http://rightsstatements.org/vocab/InC/1.0/</dc:rights>
    
  
    
  <dc:format>application/pdf</dc:format>
    
  
    
  <dc:title xml:lang="eng">Parsing YAML is a minefield</dc:title>
    
  
    
  <dc:subject xml:lang="eng">YAML</dc:subject>
    
  <dc:subject xml:lang="eng">parser compliance</dc:subject>
    
  <dc:subject xml:lang="eng">differential testing</dc:subject>
    
  <dc:subject xml:lang="eng">robustness</dc:subject>
    
  <dc:subject xml:lang="eng">Denial of Service</dc:subject>
    
  
    
  <dc:type xml:lang="eng">text</dc:type>
    
  <dc:type xml:lang="eng">other</dc:type>
    
  
    
  <dc:type xml:lang="deu">sonstige</dc:type>
    
  
    
  <dc:description xml:lang="eng">The user-friendly data serialization format known as YAML Ain&#39;t Markup Language (YAML) is widely used in cloud infrastructure, machine-to-machine communication, and configuration files, among other applications. Consistency among YAML parser libraries is essential for security, reliability, and interoperability. However, the YAML 1.2.2 specification is complex, making full compliance difficult to achieve.

To determine whether YAML 1.2 parser libraries differ from each other, a YAML Test Suite is developed. The YAML Test Suite includes 16 YAML 1.2 parser libraries and 245 YAML test case files that are created by reading the YAML 1.2.2 specification. The results are then automatically evaluated to determine whether the YAML parser libraries correctly parse a file or not. Additionally, timeouts and crashes are also tracked.

The results of the YAML Test Suite present that, while all parsing libraries can parse more than 50% of YAML test case files correctly, no YAML parsing library is completely compliant with the YAML 1.2.2 specification. Sometimes valid YAML test case files are rejected, and on other occasions invalid YAML test case files are accepted. It is also found that YAML parser libraries uniformly ignore certain features that are specified in the YAML 1.2.2 specification. In addition, no two YAML parser libraries produce the same results when supplied with the same set of YAML test case files.

In addition, potential Denial of Service (DoS) vulnerabilities are found. It is found that 14 out of 16 YAML parser libraries run into a timeout at least once during the run of the YAML Test Suite. The libraries _HsYAML_ and _YamlReference_ are further analyzed and are found to have a nonlinear increase in execution time during the parsing of a YAML test case file that contains an immense amount of nesting. Moreover, the YAML parser libraries _yaml-rust_ and _YamlDotNet_ produce a stack overflow error. While both libraries crash on different YAML test case files, the underlying issue is the same. When a sequence is deeply nested, a stack overflow error happens. Applications that use these libraries for parsing user-supplied YAML input can be susceptible to DoS attacks.

In conclusion, compliance with the YAML 1.2.2 specification is given only partially and inconsistently across YAML parser libraries. This undermines the effectiveness of the YAML 1.2.2 specification. Therefore, the behavior of YAML parsing libraries is unpredictable and incompatible, particularly because no two YAML parsing libraries generate identical results.</dc:description>
    
  
    
  <dc:language>eng</dc:language>
    
  
    
  <dc:contributor>Michael Kirchner</dc:contributor>
    
  
    
  <dc:identifier>https://phaidra.ustp.at/o:7796</dc:identifier>
    
  
</oai_dc:dc>
