CVE-2026-59869High· 7.5▾ Twilightjs-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where e…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
0.4% → 0.5%
js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.
js-yaml >= 3.0.0, < 3.15.0js-yaml >= 4.0.0, < 4.3.0Upgrade past the affected range:
js-yaml 4.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84375High· 7.5js-yaml is a JavaScript YAML parser and dumper
GHSA-5p4m-2wfm-xmqjHigh· 7.5JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
GHSA-pm4m-ph32-ghv5High· 7.5js-yaml: Exponential parsing time in flow collections leads to denial of service
CVE-2026-59870Medium· 5.3js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
CVE-2026-59868Medium· 5.3js-yaml is a JavaScript YAML parser and dumper
CVE-2024-23684High· 7.5Inefficient algorithmic complexity in DecodeFromBytes function in com.upokecenter.cbor Java implementation of Concise Binary Object Representation (CBOR) versions 4.0.0 to 4.5.1 allows an attacker to cause a denial of service by passing …