github.com
https://github.com/nodeca/js-yaml/commit/a567ef3c6e61eb319f0bfc2671d91061afb01235 GHSA-2PR6-76VF-7546
Denial of Service in js-yaml
Description
Versions of `js-yaml` prior to 3.13.0 are vulnerable to Denial of Service. By parsing a carefully-crafted YAML file, the node process stalls and may exhaust system resources leading to a Denial of Service. ## Recommendation Upgrade to version 3.13.0.
Description source: GitHub Advisory
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
js-yamlBrowse npm / js-yaml | GitHub Advisory | Before 3.13.0 · Fixed in 3.13.0 | affected |
References
5github.com
https://github.com/nodeca/js-yaml/issues/475 snyk.io
https://snyk.io/vuln/SNYK-JS-JSYAML-173999 npmjs.com
https://www.npmjs.com/advisories/788 npmjs.com
https://www.npmjs.com/advisories/788/versions