CVE-2026-59869

HIGH

js-yaml: YAML merge-key chains can force quadratic CPU consumption

Title source: cna
STIX 2.1

Description

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.

Scores

CVSS v3 7.5
EPSS 0.0042
EPSS Percentile 34.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-407
Status published
Products (5)
nodeca/js-yaml 3.0.0 - 3.15.0
nodeca/js-yaml >= 3.0.0, < 3.15.0
nodeca/js-yaml >= 4.0.0, < 4.3.0
npm/js-yaml 3.0.0 - 3.15.0npm
npm/js-yaml 4.0.0 - 4.3.0npm
Published Jul 08, 2026
Tracked Since Jul 08, 2026