
Fedora ships nodejs and yarnpkg updates resolving js-yaml prototype pollution CVE-2025-64718 on Fedora 42-43, released Mar 7 2026; admins should update via dnf. #Vulnerability https://threatcluster.io/cluster/fedora-updates-address-js-yaml-prototype-pollution-vulnerabi-1443cb46
Post summary
Fedora releases updates for nodejs and yarnpkg to fix the js‑yaml prototype pollution vulnerability (CVE‑2025‑64718); administrators should apply the patch via dnf.
