CVE-2026-59869
EUVD-2026-4230108.07.2026, 16:16
js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nodeca | js-yaml | 3.0.0 ≤ 𝑥 < 3.15.0 |
| nodeca | js-yaml | 4.0.0 ≤ 𝑥 < 4.3.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Vulnerability Media Exposure
References