Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-r3ph-w7gj-g6xm
  • npm/js-yaml
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources 3 days ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-2883-xcg3-v3hh
  • npm/js-yaml
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources 08 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-5p4m-2wfm-xmqj
  • npm/js-yaml
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported 06 Aug
  • Fix available
  • Severity - 7.5 (High)
GHSA-pm4m-ph32-ghv5
  • npm/js-yaml
js-yaml: Exponential parsing time in flow collections leads to denial of service 24 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-g796-fgmg-93mv
  • npm/js-yaml
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml 20 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-52cp-r559-cp3m
  • npm/js-yaml
js-yaml: YAML merge-key chains can force quadratic CPU consumption 20 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-724g-mxrg-4qvm
  • npm/js-yaml
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA 20 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-h67p-54hq-rp68
  • npm/js-yaml
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases 15 Jun
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-mh29-5h37-fv8m
  • npm/js-yaml
js-yaml has prototype pollution in merge (<<) 14 Nov 2025
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-2pr6-76vf-7546
  • npm/js-yaml
Denial of Service in js-yaml 05 Jun 2019
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-8j8c-7jfh-h6hx
  • npm/js-yaml
Code Injection in js-yaml 04 Jun 2019
  • Fix available
GHSA-xxvw-45rp-3mj2
  • npm/js-yaml
Deserialization Code Execution in js-yaml 24 Oct 2017
  • Fix available