js-yaml is vulnerable to Denial of Service (DoS)
75
High Risk
Affected versions of this package are vulnerable to Denial of Service (DoS) because the maxTotalMergeKeys safeguard does not count empty mappings during merge processing. A crafted YAML document that repeatedly merges a large sequence of empty mappings generates work while the merge-key counter stays unchanged, bypassing the configured protection. Parsing such a document consumes significant CPU and can make the application unavailable. The fix counts each merge-source mapping as a budget unit in addition to counting its keys.
You are affected if your application uses an affected version to parse untrusted YAML input.
js-yaml is vulnerable to Denial of Service (DoS) in versions 3.0.0 - 3.15.1 and 4.0.0 - 4.3.1.
Upgrade the js-yaml library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.