Threat Advisory

js-yaml Flaw Consumes CPU with Empty Merge Sources

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability, CVE-2026-84375 with a CVSS score of 7.5, exists in the js-yaml package due to an issue with its maxTotalMergeKeys feature. This flaw allows an attacker to repeatedly merge large sequences of empty mappings and consume significant CPU without reaching the configured limit, resulting in prolonged CPU consumption despite the default maxTotalMergeKeys limit. The affected versions are greater than or equal to 4.0.0 and less than 4.3.2, as well as greater than or equal to 3.0.0 and less than 3.15.2. This vulnerability can be exploited through an attack vector of network access with a low complexity attack, resulting in high availability impact on the system. The flaw type is a resource exhaustion issue, which allows an attacker to consume excessive CPU resources without being detected. If left unaddressed, this vulnerability can lead to significant business impact, including prolonged downtime and potential data loss due to the prolonged CPU consumption.

RECOMMENDATION:

We recommend you to update js-yaml to version 4.3.2 or 3.15.2.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability, CVE-2026-84375 with a CVSS score of 7.5, exists in the js-yaml package due to an issue with its maxTotalMergeKeys feature. This flaw allows an attacker to repeatedly merge large sequences of empty mappings and consume significant CPU without reaching the configured limit, resulting in prolonged CPU consumption despite the default maxTotalMergeKeys limit. The affected versions are greater than or equal to 4.0.0 and less than 4.3.2, as well as greater than or equal to 3.0.0 and less than 3.15.2. This vulnerability can be exploited through an attack vector of network access with a low complexity attack, resulting in high availability impact on the system. The flaw type is a resource exhaustion issue, which allows an attacker to consume excessive CPU resources without being detected. If left unaddressed, this vulnerability can lead to significant business impact, including prolonged downtime and potential data loss due to the prolonged CPU consumption.

RECOMMENDATION:

We recommend you to update js-yaml to version 4.3.2 or 3.15.2.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu