{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/js-yaml--4.0.0--4.3.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-84375"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["js-yaml (\u003e= 4.0.0, \u003c 4.3.2)","js-yaml (\u003e= 3.0.0, \u003c 3.15.2)"],"_cs_severities":["low"],"_cs_tags":["vulnerability","denial-of-service","supply-chain"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe js-yaml library (versions 3.x \u0026lt; 3.15.2 and 4.x \u0026lt; 4.3.2) is vulnerable to a denial-of-service (DoS) condition due to an incorrect implementation of merge key counting. The \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e configuration is intended to limit the computational complexity of parsing YAML documents; however, it does not count empty mappings towards this limit. An attacker can supply a YAML payload consisting of a large sequence of empty mappings that are repeatedly merged, resulting in an O(N*K) complexity increase. This allows for high CPU utilization using a relatively small file size, effectively bypassing configured protections. This vulnerability (CVE-2026-84375) is particularly impactful in applications that accept untrusted YAML input, as the parser consumes excessive cycles, potentially leading to resource exhaustion and service unavailability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in high CPU consumption, causing service degradation or total unavailability for applications parsing malicious YAML documents. This is a supply chain vulnerability affecting any JavaScript application that relies on the \u003ccode\u003ejs-yaml\u003c/code\u003e library for processing user-supplied data, such as configuration files, user data imports, or API requests.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade \u003ccode\u003ejs-yaml\u003c/code\u003e to versions 3.15.2 or 4.3.2 or later to include the fix that correctly counts empty merge-source mappings.\u003c/li\u003e\n\u003cli\u003ePerform a dependency audit of your projects using \u003ccode\u003enpm list js-yaml\u003c/code\u003e or \u003ccode\u003eyarn why js-yaml\u003c/code\u003e to identify vulnerable versions.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, implement strict file size limits and timeout configurations on any server-side service that triggers the \u003ccode\u003ejs-yaml\u003c/code\u003e parser on untrusted input.\u003c/li\u003e\n\u003cli\u003eEnsure that the \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e configuration is enabled and set to a strict value appropriate for your application requirements.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-08T21:50:18Z","date_published":"2026-09-08T21:50:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-js-yaml-dos/","summary":"The js-yaml library fails to correctly account for empty mappings when enforcing maxTotalMergeKeys, allowing attackers to trigger excessive CPU consumption through specially crafted YAML documents.","title":"Denial of Service Vulnerability in js-yaml via Empty Merge Source Exhaustion","url":"https://feed.craftedsignal.io/briefs/2026-09-js-yaml-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Js-Yaml (\u003e= 4.0.0, \u003c 4.3.2)","version":"https://jsonfeed.org/version/1.1"}