PT-2026-56490 · Npm · Js-Yaml

·

CVE-2026-59869

·

Published

2026-07-08

·

Updated

2026-07-28

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions js-yaml versions 3.0.0 through 3.14.x js-yaml versions 4.0.0 through 4.2.x
Description js-yaml can consume quadratic CPU time when parsing a document that grows linearly in size. This occurs when a chain of mappings utilizes merge keys, where each subsequent mapping merges the previous one.
Recommendations Update js-yaml versions 3.0.0 through 3.14.x to version 3.15.0. Update js-yaml versions 4.0.0 through 4.2.x to version 4.3.0.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92192
CVE-2026-59869
GHSA-52CP-R559-CP3M
RHSA-2026:37532
RHSA-2026:37534
RHSA-2026:38304
RHSA-2026:40415
RHSA-2026:9455

Affected Products

Js-Yaml