Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-59868

Опубликовано: 08 июл. 2026
Источник: debian

Описание

js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.0, when merge keys are enabled, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in version 5.2.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-js-yamlnot-affectedpackage

Примечания

  • https://github.com/nodeca/js-yaml/security/advisories/GHSA-g796-fgmg-93mv

  • Fixed by: https://github.com/nodeca/js-yaml/commit/3105455b81dee69e0fd36e09ac0b2ccfdb54adc1 (5.2.0)

Связанные уязвимости

CVSS3: 5.3
ubuntu
26 дней назад

js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.0, when merge keys are enabled, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in version 5.2.0.

CVSS3: 7.5
redhat
26 дней назад

js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.0, when merge keys are enabled, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in version 5.2.0.

CVSS3: 5.3
nvd
26 дней назад

js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.0, when merge keys are enabled, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in version 5.2.0.

CVSS3: 5.3
github
14 дней назад

js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml