VulnSea

js-yaml vulnerabilities

CVEs whose affected-version data names the js-yaml package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-84375High· 7.5
3w ago

js-yaml is a JavaScript YAML parser and dumper

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias…

Twilightjs-yaml · js-yamlEPSS 0.39%via NVD
GHSA-5p4m-2wfm-xmqjHigh· 7.5
1mo ago

JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported

JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported

Twilightjs-yaml · js-yamlvia GHSA
GHSA-pm4m-ph32-ghv5High· 7.5
2mo ago

js-yaml: Exponential parsing time in flow collections leads to denial of service

js-yaml: Exponential parsing time in flow collections leads to denial of service

Twilightjs-yaml · js-yamlvia GHSA
CVE-2026-59870Medium· 5.3
2mo ago

js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA

js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA

Sunlitjs-yaml · js-yamlEPSS 0.64%via GHSA
CVE-2026-59869High· 7.5
2mo ago

js-yaml is a JavaScript YAML parser and dumper

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where e…

Twilightnodeca · js-yamlEPSS 0.54%via NVD
CVE-2026-59868Medium· 5.3
2mo ago

js-yaml is a JavaScript YAML parser and dumper

js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.0, when merge keys are enabled, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where e…

Sunlitnodeca · js-yamlEPSS 0.64%via NVD
js-yaml vulnerabilities (CVEs) · VulnSea