Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-53550

Опубликовано: 22 июн. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerability is fixed in 4.2.0 and 3.15.0.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:nodeca:js-yaml:*:*:*:*:*:node.js:*:*
Версия до 3.15.0 (исключая)
cpe:2.3:a:nodeca:js-yaml:*:*:*:*:*:node.js:*:*
Версия от 4.0.0 (включая) до 4.2.0 (исключая)

EPSS

Процентиль: 18%
0.00259
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-407

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerability is fixed in 4.2.0 and 3.15.0.

CVSS3: 5.3
redhat
около 1 месяца назад

js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerability is fixed in 4.2.0 and 3.15.0.

CVSS3: 5.3
debian
около 1 месяца назад

js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.1 ...

CVSS3: 5.3
github
около 2 месяцев назад

JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases

suse-cvrf
около 1 месяца назад

Security update for python-pytest-html

EPSS

Процентиль: 18%
0.00259
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-407