Versions of js-yaml prior to 3.13.0 are vulnerable to Denial of Service. By parsing a carefully-crafted YAML file, the node process stalls and may exhaust system resources leading to a Denial of Service.
Upgrade to version 3.13.0.
{
"cwe_ids": [
"CWE-400"
],
"github_reviewed_at": "2019-06-05T13:52:07Z",
"nvd_published_at": null,
"github_reviewed": true,
"severity": "MODERATE"
}