Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59869

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.

A flaw was found in js-yaml, a JavaScript YAML parser and dumper. A remote attacker could exploit this vulnerability by providing a specially crafted YAML document containing a chain of mappings with merge keys. This could cause the parser to consume excessive CPU resources, leading to a Denial of Service (DoS) for the affected system.

Отчет

This vulnerability is rated as Important. Red Hat products utilizing js-yaml to process untrusted YAML input are susceptible to a denial of service, as a remote attacker can provide a crafted document that consumes excessive CPU resources. This is considered Important due to the potential for service disruption without requiring authentication or complex attack vectors.

Меры по смягчению последствий

To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on js-yaml. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat/cryostat-openshift-console-plugin-rhel9Under investigation
Cryostat 4cryostat-openshift-console-plugin-npmUnder investigation
Cryostat 4grafana-infinity-datasource-npmUnder investigation
Cryostat 4js-yamlAffected
Gatekeeper 3gatekeeper/gatekeeper-rhel9Not affected
Migration Toolkit for Applications 8mta/mta-ui-rhel8Under investigation
Migration Toolkit for Applications 8mta/mta-ui-rhel9Under investigation
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Affected
Network Observability Operatornetwork-observability/network-observability-console-plugin-pf5-rhel9Affected
Network Observability Operatornetwork-observability/network-observability-console-plugin-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-606
https://bugzilla.redhat.com/show_bug.cgi?id=2498122js-yaml: js-yaml: Denial of Service via crafted YAML documents

EPSS

Процентиль: 35%
0.00423
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
24 дня назад

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.

CVSS3: 7.5
nvd
24 дня назад

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.

msrc
22 дня назад

js-yaml: YAML merge-key chains can force quadratic CPU consumption

CVSS3: 7.5
debian
24 дня назад

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15 ...

CVSS3: 7.5
github
12 дней назад

js-yaml: YAML merge-key chains can force quadratic CPU consumption

EPSS

Процентиль: 35%
0.00423
Низкий

7.5 High

CVSS3