All 7 CVE vulnerabilities found in js-yaml, with AI-generated Chinese analysis, references, and POCs.
Vendor: nodeca
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-84375 | js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources CWE-400 | 7.5 | High | 2026-09-01 |
| CVE-2026-73643 | js-yaml: Exponential parsing time in the flow collections leads to denial of service CWE-407 | 7.5 | High | 2026-08-13 |
| CVE-2026-59868 | js-yaml: YAML merge-key chains can force quadratic CPU consumption CWE-407 | 5.3 | Medium | 2026-07-08 |
| CVE-2026-59869 | js-yaml: YAML merge-key chains can force quadratic CPU consumption CWE-407 | 7.5 | High | 2026-07-08 |
| CVE-2026-59870 | js-yaml quadratic-complexity denial of service via YAML11_SCHEMA !!omap parsing CWE-407 | 5.3 | Medium | 2026-07-08 |
| CVE-2026-53550 | js-yaml: Quadratic-complexity DoS in merge key handling via repeated aliases CWE-407 | 5.3 | Medium | 2026-06-22 |
| CVE-2025-64718 | js-yaml has prototype pollution in merge (<<) CWE-1321 | 5.3 | Medium | 2025-11-13 |
All 7 known CVE vulnerabilities affecting js-yaml with full Chinese analysis, references, and POCs where available.