nodeca js-yaml
4 known vulnerabilities in nodeca js-yaml, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-84375 CVSS 7.5 high js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2, 4.3.2, and 5.4.1, maxTotalMergeKeys in lib/js-yaml/loader.js and…
- CVE-2026-59869 CVSS 7.5 high js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time…
- CVE-2026-53550 CVSS 5.3 medium js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion…
- CVE-2025-64718 CVSS 5.3 medium js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype…