Category

Js Yaml

Security vulnerabilities and automated fixes for js yaml issues

4 posts found

high6 min

How Quadratic Complexity Denial of Service happens in JavaScript YAML parsing and how to fix it

A high-severity dependency vulnerability in `js-yaml`, used transitively by `electron-builder`/`electron-updater` inside the DSA Desktop app, allowed attacker-controlled YAML with `!!omap` tags to trigger quadratic-time CPU consumption during parsing. The fix pins `js-yaml` to the patched `4.3.1` (and `3.15.1` for the legacy branch) release via both `package.json` overrides and `package-lock.json`.

#security#denial-of-service#js-yaml+4 more
A
anupamme
Sep 7, 2026
high7 min

How Denial of Service happens in js-yaml (Node.js) and how to fix it

A high-severity Denial of Service vulnerability (CVE-2026-59869) in the js-yaml parser allowed specially crafted YAML documents to exhaust CPU and memory when loaded by apps/dsa-desktop. The fix upgrades js-yaml to a patched release via the package-lock.json dependency tree, closing off the unbounded resource consumption path before it reached production.

#security#denial-of-service#js-yaml+3 more
A
anupamme
Aug 31, 2026
high7 min

How Quadratic CPU Consumption in js-yaml's !!omap Resolution Happens in Node.js and How to Fix It

A high-severity algorithmic complexity vulnerability (GHSA-5p4m-2wfm-xmqj) in js-yaml versions 3.x through 4.3.0 allows attackers to trigger quadratic CPU consumption through specially crafted `!!omap` YAML sequences. The fix upgrades js-yaml to 4.3.1 using a pnpm override in the `e2e/adapter/claude-code` package, ensuring all transitive dependencies also receive the patched version. This proactive patch eliminates an exploit primitive before it can be chained with other weaknesses.

#deserialization#javascript#nodejs+5 more
A
anupamme
Aug 30, 2026
high8 min

How Quadratic CPU Consumption happens in JavaScript YAML parsing and how to fix it

A high-severity denial-of-service vulnerability (GHSA-5p4m-2wfm-xmqj) in js-yaml versions 4.3.0 and 3.x caused quadratic CPU consumption when resolving `!!omap` (ordered map) types in YAML documents. Attackers who could supply crafted YAML input could cause CPU exhaustion proportional to the square of the input size, potentially grinding Node.js services to a halt. The fix upgrades js-yaml to 4.3.1 and pins the version via a `package.json` overrides block to ensure no transitive dependency can r

#security#javascript#nodejs+5 more
A
anupamme
Aug 9, 2026