Product
medium
advisory
js-yaml Denial of Service via Exponential Parsing Time in Flow Collections
1 TTPA denial of service vulnerability exists in the js-yaml library (versions 5.0.0 through 5.2.1) due to an exponential parsing time bug in flow collections, allowing attackers to craft a small YAML document which, when processed by `load()` or `loadAll()` functions, consumes significant CPU resources and blocks the Node.js event loop.
js-yaml
denial-of-service
yaml
javascript
vulnerability
1t
medium
threat
CVE-2026-59869: js-yaml Vulnerability Leading to Quadratic CPU Consumption and DoS
2 TTPs 1 CVEA vulnerability, CVE-2026-59869, in the `js-yaml` library allows attackers to craft malicious YAML merge-key chains, which can lead to quadratic CPU consumption and a Denial of Service condition in applications processing the input.
exploited
js-yaml
denial-of-service
vulnerability
yaml
2t
1c