CVE-2026-59869Patch(nodeca / js-yaml)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nodeca js-yaml systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-407

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • js-yaml

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-07-09); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
js-yaml

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-09: 1Mentions · 2026-07-13: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-07-13: 1Technical Details · 2026-07-09: 1Technical Details · 2026-07-13: 107-0907-13
Signal classification1 categories
Patch
2100.0%
Full discourse2 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-59869 (CVSS 7.5) js-yaml parser vulnerable to quadratic CPU exhaustion via merge key chains. Affects v3.0.0-3.14.x & v4.0.0-4.2.x. ✅ Patch: Update to 3.15.0 or 4.3.0 #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/tHCNafYdWH

    Post summary

    The tweet announces CVE-2026-59869, explains it as a quadratic CPU exhaustion issue in js-yaml, and provides patch versions 3.15.0 or 4.3.0.

    0000044
    71 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HIGH - js-yaml YAML merge key parsing CPU DoS (CVE-2026-59869) js-yaml is vulnerable to inefficient algorithmic complexity in its YAML parser when handling long chains of mappings that use merge keys to repeatedly merge the previous mapping. The root cause is an algorithmic complexity issue (quadratic-time behavior) triggered by pathological merge-key resolution during parsing. An attacker can exploit this by supplying a crafted YAML document (often via any feature that accepts user-controlled YAML, like config import, CI pipelines, or web APIs) with input size that grows linearly but forces the parser into quadratic CPU work, requiring no special privileges beyond the ability to submit YAML for parsing. Impact is denial of service via CPU exhaustion, causing request timeouts, worker starvation, and service instability. 👉 Affected: js-yaml <3.15.0 and >=4.0.0 <4.3.0 | Upgrade to 3.15.0 or 4.3.0

    Post summary

    The advisory discloses a CPU‑based DoS flaw in js‑yaml’s merge‑key parsing and recommends upgrading to version 3.15.0 or 4.3.0.

    0000076
    246 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodecajs-yaml-node.js-

Explore more