Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59870

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 5.3
CVSS3: 7.5
EPSS Низкий

Описание

js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.1, YAML11_SCHEMA support for the !!omap tag in src/tag/sequence/omap.ts uses omapTag.addItem() to perform a linear duplicate-key scan on every insertion, causing O(n^2) CPU consumption when yaml.load() parses a crafted ordered-map document. This issue is fixed in version 5.2.1.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nodeca:js-yaml:*:*:*:*:*:node.js:*:*
Версия от 5.0.0 (включая) до 5.2.1 (исключая)

EPSS

Процентиль: 34%
0.0041
Низкий

5.3 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-407
CWE-770

Связанные уязвимости

CVSS3: 5.3
ubuntu
26 дней назад

js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.1, YAML11_SCHEMA support for the !!omap tag in src/tag/sequence/omap.ts uses omapTag.addItem() to perform a linear duplicate-key scan on every insertion, causing O(n^2) CPU consumption when yaml.load() parses a crafted ordered-map document. This issue is fixed in version 5.2.1.

CVSS3: 7.5
redhat
26 дней назад

js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.1, YAML11_SCHEMA support for the !!omap tag in src/tag/sequence/omap.ts uses omapTag.addItem() to perform a linear duplicate-key scan on every insertion, causing O(n^2) CPU consumption when yaml.load() parses a crafted ordered-map document. This issue is fixed in version 5.2.1.

CVSS3: 5.3
debian
26 дней назад

js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2. ...

CVSS3: 5.3
github
14 дней назад

js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA

EPSS

Процентиль: 34%
0.0041
Низкий

5.3 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-407
CWE-770