Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33532

Опубликовано: 26 мар. 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

yaml is a YAML parser and serialiser for JavaScript. Parsing a YAML document with a version of yaml on the 1.x branch prior to 1.10.3 or on the 2.x branch prior to 2.8.3 may throw a RangeError due to a stack overflow. The node resolution/composition phase uses recursive function calls without a depth bound. An attacker who can supply YAML for parsing can trigger a RangeError: Maximum call stack size exceeded with a small payload (~2–10 KB). The RangeError is not a YAMLParseError, so applications that only catch YAML-specific errors will encounter an unexpected exception type. Depending on the host application's exception handling, this can fail requests or terminate the Node.js process. Flow sequences allow deep nesting with minimal bytes (2 bytes per level: one [ and one ]). On the default Node.js stack, approximately 1,000–5,000 levels of nesting (2–10 KB input) exhaust the call stack. The exact threshold is environment-dependent (Node.js version, stack size, call

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:eemeli:yaml:*:*:*:*:*:node.js:*:*
Версия от 1.0.0 (включая) до 1.10.3 (исключая)
cpe:2.3:a:eemeli:yaml:*:*:*:*:*:node.js:*:*
Версия от 2.0.0 (включая) до 2.8.3 (исключая)

EPSS

Процентиль: 38%
0.0047
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-674

Связанные уязвимости

CVSS3: 4.3
ubuntu
5 месяцев назад

`yaml` is a YAML parser and serialiser for JavaScript. Parsing a YAML document with a version of `yaml` on the 1.x branch prior to 1.10.3 or on the 2.x branch prior to 2.8.3 may throw a RangeError due to a stack overflow. The node resolution/composition phase uses recursive function calls without a depth bound. An attacker who can supply YAML for parsing can trigger a `RangeError: Maximum call stack size exceeded` with a small payload (~2–10 KB). The `RangeError` is not a `YAMLParseError`, so applications that only catch YAML-specific errors will encounter an unexpected exception type. Depending on the host application's exception handling, this can fail requests or terminate the Node.js process. Flow sequences allow deep nesting with minimal bytes (2 bytes per level: one `[` and one `]`). On the default Node.js stack, approximately 1,000–5,000 levels of nesting (2–10 KB input) exhaust the call stack. The exact threshold is environment-dependent (Node.js version, stack size, c...

CVSS3: 6.5
redhat
5 месяцев назад

`yaml` is a YAML parser and serialiser for JavaScript. Parsing a YAML document with a version of `yaml` on the 1.x branch prior to 1.10.3 or on the 2.x branch prior to 2.8.3 may throw a RangeError due to a stack overflow. The node resolution/composition phase uses recursive function calls without a depth bound. An attacker who can supply YAML for parsing can trigger a `RangeError: Maximum call stack size exceeded` with a small payload (~2–10 KB). The `RangeError` is not a `YAMLParseError`, so applications that only catch YAML-specific errors will encounter an unexpected exception type. Depending on the host application's exception handling, this can fail requests or terminate the Node.js process. Flow sequences allow deep nesting with minimal bytes (2 bytes per level: one `[` and one `]`). On the default Node.js stack, approximately 1,000–5,000 levels of nesting (2–10 KB input) exhaust the call stack. The exact threshold is environment-dependent (Node.js version, stack size, c...

CVSS3: 4.3
debian
5 месяцев назад

`yaml` is a YAML parser and serialiser for JavaScript. Parsing a YAML ...

CVSS3: 4.3
github
5 месяцев назад

yaml is vulnerable to Stack Overflow via deeply nested YAML collections

CVSS3: 4.3
fstec
5 месяцев назад

Уязвимость библиотеки синтаксического анализа документов формата YAML yaml, связанная с неконтролируемой рекурсией, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 38%
0.0047
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-674