Zurück zur CVE-Übersicht
CVE-2026-59869
HIGH(7.5)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Risk Signal Score19/100 — NIEDRIG
- CVSS 7.5 — Hoch
Erwähnungen (letzte 60 Tage)
Artikel
EPSS-Score
0.5%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
7.5
Technische Schwere
Beschreibung
js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.
GitHub Advisories
GHSA-52cp-r559-cp3mHIGH
js-yaml: YAML merge-key chains can force quadratic CPU consumption
npm/js-yaml→ 3.15.0
GitHub AdvisoryReferenzen
- https://github.com/nodeca/js-yaml/commit/24f13e79ee1343a7e30bd6f6c9d9cdbf0ac9b2b...
- https://github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e...
- https://github.com/nodeca/js-yaml/releases/tag/3.15.0
- https://github.com/nodeca/js-yaml/releases/tag/4.3.0
- https://github.com/nodeca/js-yaml/security/advisories/GHSA-52cp-r559-cp3m
- https://github.com/nodeca/js-yaml/security/advisories/GHSA-52cp-r559-cp3m