Browse all 7 CVE security advisories affecting nodeca. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-84375 | js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources — js-yaml CWE-400 | 7.5 | High | 2026-09-01 |
| CVE-2026-73643 | js-yaml: Exponential parsing time in the flow collections leads to denial of service — js-yaml CWE-407 | 7.5 | High | 2026-08-13 |
| CVE-2026-59868 | js-yaml: YAML merge-key chains can force quadratic CPU consumption — js-yaml CWE-407 | 5.3 | Medium | 2026-07-08 |
| CVE-2026-59869 | js-yaml: YAML merge-key chains can force quadratic CPU consumption — js-yaml CWE-407 | 7.5 | High | 2026-07-08 |
| CVE-2026-59870 | js-yaml quadratic-complexity denial of service via YAML11_SCHEMA !!omap parsing — js-yaml CWE-407 | 5.3 | Medium | 2026-07-08 |
| CVE-2026-53550 | js-yaml: Quadratic-complexity DoS in merge key handling via repeated aliases — js-yaml CWE-407 | 5.3 | Medium | 2026-06-22 |
| CVE-2025-64718 | js-yaml has prototype pollution in merge (<<) — js-yaml CWE-1321 | 5.3 | Medium | 2025-11-13 |
This page lists every published CVE security advisory associated with nodeca. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.