js-yaml is vulnerable to Denial of Service (DoS)
53
Medium Risk
Affected versions of this package are vulnerable to Denial of Service (DoS) because the maxTotalMergeKeys safeguard does not account for empty mappings during merge processing. A crafted YAML document that repeatedly merges empty mappings performs a large number of iterations without ever incrementing the merge-key counter, so the configured limit is never reached. The fix counts each merge-source mapping toward maxTotalMergeKeys and hard-limits the size of merge sequences.
You are affected if your application uses an affected version to parse untrusted YAML input.
js-yaml is vulnerable to Denial of Service (DoS) in versions 5.0.0 - 5.4.0.
Upgrade the js-yaml library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.