Overview
A flaw was found in js-yaml, a JavaScript YAML parser and dumper. A remote attacker can exploit this vulnerability by providing a specially crafted YAML document that repeatedly uses the same alias in a merge sequence. This can lead to algorithmic CPU exhaustion, causing the Node.js worker or event loop to be blocked for an extended period, resulting in a denial of service (DoS) for the affected system.
Vendor advisories
- RHSA-2026:38236 · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-11 · advisory
- RHSA-2026:37534 · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-10 · advisory
- RHSA-2026:33866 · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-30 · advisory
- RHSA-2026:65126 · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-09-08 · advisory
- RHSA-2026:60520 · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · advisory
- RHSA-2026:56431 · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.18 · released 2026-08-18 · advisory
- Red Hat VEX · Moderate · affected: Cryostat 4, Migration Toolkit for Applications 8, Migration Toolkit for Containers, Multicluster Engine for Kubernetes, Network Observability Operator, Node HealthCheck Operator, … · no fix planned: Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Hardened Images, Cryostat 4, Migration Toolkit for Applications 8, … · updated 2026-09-08 · vex
js-yaml: js-yaml: Denial of Service via crafted YAML merge keys — rated Moderate by Red Hat. Released 2026-06-22, updated 2026-09-08.
Affected:
- Cryostat 4
- Migration Toolkit for Applications 8
- Migration Toolkit for Containers
- Multicluster Engine for Kubernetes
- Network Observability Operator
- Node HealthCheck Operator
- OpenShift Lightspeed
- OpenShift Pipelines
- OpenShift Service Mesh 2
- OpenShift Service Mesh 3
- Red Hat 3scale API Management Platform 2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 4
- Red Hat AMQ Broker 7
- Red Hat Ansible Automation Platform 2
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat build of Apache Camel for Spring Boot 4
- Red Hat build of Apicurio Registry 3
- Red Hat Build of Keycloak
- Red Hat Build of Podman Desktop
- Red Hat Ceph Storage 9
- Red Hat Connectivity Link 1
- Red Hat Data Grid 8
- Red Hat Developer Hub
- Red Hat Directory Server 11
- Red Hat Directory Server 12
- Red Hat Discovery 2
- Red Hat Edge Manager 1
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat Fuse 7
- Red Hat Hardened Images
- Red Hat JBoss Enterprise Application Platform 7
- Red Hat JBoss Enterprise Application Platform 8
- Red Hat JBoss Enterprise Application Platform Expansion Pack
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift Dev Spaces
Fixed:
- Red Hat Hardened Images
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.4
- Red Hat Openshift Data Foundation 4.18
No fix planned:
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat Hardened Images
- Cryostat 4
- Migration Toolkit for Applications 8
- Migration Toolkit for Containers
- Multicluster Engine for Kubernetes
- Network Observability Operator
- Node HealthCheck Operator
- OpenShift Lightspeed
- OpenShift Pipelines
- OpenShift Service Mesh 2
- OpenShift Service Mesh 3
- Red Hat 3scale API Management Platform 2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 4
- Red Hat AMQ Broker 7
- Red Hat Ansible Automation Platform 2
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat build of Apache Camel for Spring Boot 4
- Red Hat build of Apicurio Registry 3
- Red Hat Build of Keycloak
- Red Hat Build of Podman Desktop
- Red Hat Ceph Storage 9
- Red Hat Connectivity Link 1
- Red Hat Data Grid 8
- Red Hat Developer Hub
- Red Hat Directory Server 11
- Red Hat Directory Server 12
- Red Hat Discovery 2
- Red Hat Edge Manager 1
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Fuse 7
- Red Hat JBoss Enterprise Application Platform 7
- Red Hat JBoss Enterprise Application Platform 8
- Red Hat JBoss Enterprise Application Platform Expansion Pack
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift Dev Spaces
- Red Hat OpenShift GitOps
Not affected:
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.4
- Red Hat Openshift Data Foundation 4.18
- Gatekeeper 3
- Red Hat Directory Server 13
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Hardened Images
- Red Hat OpenShift Container Platform 4
Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:38236
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:37534
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:33866
Workarounds / mitigations:
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Package advisory (CVE-2026-53550)
Affected packages:
js-yaml >= 4.0.0, <= 4.1.1
js-yaml < 3.15.0
Patched in:
js-yaml 4.2.0
js-yaml 3.15.0
Source: https://github.com/advisories/GHSA-h67p-54hq-rp68