Signal is active with 1 mentions in latest observed window
Immediate actions
Patch nodeca js-yaml systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.
🚨 HIGH: CVE-2026-59869 (CVSS 7.5)
js-yaml parser vulnerable to quadratic CPU exhaustion via merge key chains. Affects v3.0.0-3.14.x & v4.0.0-4.2.x.
✅ Patch: Update to 3.15.0 or 4.3.0
#CVE#Vulnerability#PatchNow#ThreatIntel https://t.co/tHCNafYdWH
Post summary
The tweet announces CVE-2026-59869, explains it as a quadratic CPU exhaustion issue in js-yaml, and provides patch versions 3.15.0 or 4.3.0.
🚨 HIGH - js-yaml YAML merge key parsing CPU DoS (CVE-2026-59869)
js-yaml is vulnerable to inefficient algorithmic complexity in its YAML parser when handling long chains of mappings that use merge keys to repeatedly merge the previous mapping. The root cause is an algorithmic complexity issue (quadratic-time behavior) triggered by pathological merge-key resolution during parsing. An attacker can exploit this by supplying a crafted YAML document (often via any feature that accepts user-controlled YAML, like config import, CI pipelines, or web APIs) with input size that grows linearly but forces the parser into quadratic CPU work, requiring no special privileges beyond the ability to submit YAML for parsing. Impact is denial of service via CPU exhaustion, causing request timeouts, worker starvation, and service instability.
👉 Affected: js-yaml <3.15.0 and >=4.0.0 <4.3.0 | Upgrade to 3.15.0 or 4.3.0
Post summary
The advisory discloses a CPU‑based DoS flaw in js‑yaml’s merge‑key parsing and recommends upgrading to version 3.15.0 or 4.3.0.