CVE-2026-59868Medium· 5.3▾ Sunlitjs-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.0, when merge keys are enabled, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where e…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
0.3% → 0.6%
js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.0, when merge keys are enabled, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in version 5.2.0.
js-yaml >= 5.0.0, < 5.2.0Upgrade past the affected range:
js-yaml 5.2.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59870Medium· 5.3js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
CVE-2026-84375High· 7.5js-yaml is a JavaScript YAML parser and dumper
GHSA-5p4m-2wfm-xmqjHigh· 7.5JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
GHSA-pm4m-ph32-ghv5High· 7.5js-yaml: Exponential parsing time in flow collections leads to denial of service
CVE-2026-59869High· 7.5js-yaml is a JavaScript YAML parser and dumper
CVE-2026-19668Medium· 5.3A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record