CVE Vulnerabilities

CVE-2026-59869

Inefficient Algorithmic Complexity

Published: Jul 08, 2026 | Modified: Jul 13, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.

Weakness

An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Affected Software

NameVendorStart VersionEnd Version
Js-yamlNodeca3.0.0 (including)3.15.0 (excluding)
Js-yamlNodeca4.0.0 (including)4.3.0 (excluding)
Red Hat Hardened ImagesRedHatnodejs26-main-26.4.0-1.4.hum1*
Red Hat Hardened ImagesRedHatnodejs25-main-25.9.0-1.3.hum1*
Red Hat Hardened ImagesRedHatdotnet8-0-main-8.0.128-1.1.hum1*
Red Hat Hardened ImagesRedHatrust-main-1.97.0-1.1.hum1*
Red Hat Hardened ImagesRedHatnodejs24-main-24.18.0-0.3.hum1*
Red Hat Hardened ImagesRedHatnodejs22-main-22.23.1-2.1.hum1*
Node-js-yamlUbuntuquesting*

References