Количество 6
Количество 6
CVE-2026-59869
js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.
CVE-2026-59869
js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.
CVE-2026-59869
js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.
CVE-2026-59869
js-yaml: YAML merge-key chains can force quadratic CPU consumption
CVE-2026-59869
js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15 ...
GHSA-52cp-r559-cp3m
js-yaml: YAML merge-key chains can force quadratic CPU consumption
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-59869 js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0. | CVSS3: 7.5 | 0% Низкий | 25 дней назад | |
CVE-2026-59869 js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0. | CVSS3: 7.5 | 0% Низкий | 25 дней назад | |
CVE-2026-59869 js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0. | CVSS3: 7.5 | 0% Низкий | 25 дней назад | |
CVE-2026-59869 js-yaml: YAML merge-key chains can force quadratic CPU consumption | 0% Низкий | 22 дня назад | ||
CVE-2026-59869 js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15 ... | CVSS3: 7.5 | 0% Низкий | 25 дней назад | |
GHSA-52cp-r559-cp3m js-yaml: YAML merge-key chains can force quadratic CPU consumption | CVSS3: 7.5 | 0% Низкий | 12 дней назад |
Уязвимостей на страницу