CVE Vulnerabilities

CVE-2026-84375

Uncontrolled Resource Consumption

Published: Sep 01, 2026 | Modified: Sep 28, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2, 4.3.2, and 5.4.1, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key «. An attacker can alias a large sequence of empty mappings into many merge targets, causing O(N * K) processing while totalMergeKeys remains unchanged and the configured resource limit is never reached. A relatively small YAML document can therefore cause prolonged CPU consumption in applications that parse untrusted YAML, and merge processing is enabled by default on these release lines. In v3 & v4, merge is enabled by default so the severity score is higher. This issue is fixed in versions 3.15.2, 4.3.2, and 5.4.1.

Weakness

The product does not properly control the allocation and maintenance of a limited resource.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Ansible Automation Platform 2.6 for RHEL 9RedHatautomation-platform-ui-0:2.6.14-1.el9ap*
Network Observability (NETOBSERV) 1.12.3RedHatnetwork-observability/network-observability-console-plugin-pf5-rhel9:1789978780*
Network Observability (NETOBSERV) 1.12.3RedHatnetwork-observability/network-observability-console-plugin-rhel9:1789978277*
Red Hat Advanced Cluster Security for Kubernetes 4.10RedHatadvanced-cluster-security/rhacs-main-rhel8:1789411269*
Red Hat Advanced Cluster Security for Kubernetes 4.11RedHatadvanced-cluster-security/rhacs-main-rhel9:1789411320*
Red Hat Ansible Automation Platform 2.1RedHatansible-automation-platform/automation-portal:1790254963*
Red Hat Ansible Automation Platform 2.2RedHatansible-automation-platform/automation-portal:1790256405*
Red Hat Ansible Automation Platform 2.5RedHatansible-automation-platform-25/lightspeed-rhel8:1789685837*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-26/lightspeed-rhel9:1789656884*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-tech-preview/mcp-server-rhel9:1789669036*
Red Hat Ansible Automation Platform 2.7RedHatansible-automation-platform-27/mcp-server-rhel9:1788915736*
Red Hat Container Native Virtualization 4.12RedHatcontainer-native-virtualization/kubevirt-console-plugin:1789624656*
Red Hat Container Native Virtualization 4.14RedHatcontainer-native-virtualization/kubevirt-console-plugin-rhel9:1789701168*
Red Hat Container Native Virtualization 4.16RedHatcontainer-native-virtualization/kubevirt-console-plugin-rhel9:1789703476*
Red Hat Discovery 2RedHatdiscovery/discovery-ui-rhel9:1789677459*
Red Hat Edge Manager 1.1RedHatrhem/flightctl-ui-ocp-rhel10:1789486226*
Red Hat Edge Manager 1.1RedHatrhem/flightctl-ui-rhel10:1789486181*
Red Hat Edge Manager 1.1RedHatrhem/flightctl-ui-ocp-rhel9:1789486446*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-ui-ocp-rhel10:1789485920*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-ui-rhel10:1789488111*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-ui-ocp-rhel9:1789486476*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-ui-rhel9:1789486750*
Red Hat Hardened ImagesRedHatgrafana12-4-main-12.4.9-0.5.hum1*
Red Hat Hardened ImagesRedHatgrafana13-2-main-13.2.0-0.1.4.hum1*
Red Hat Hardened ImagesRedHatgrafana13-2-main-13.2.1-0.1.hum1*
Red Hat Hardened ImagesRedHatgrafana13-1-main-13.1.3-0.5.hum1*
Red Hat Migration Toolkit 1.8RedHatrhmtc/openshift-migration-ui-rhel8:1789546373*
Red Hat Migration Toolkit for Applications 8.2RedHatmta/mta-ui-rhel9:1789446780*
Red Hat OpenShift AI 3.3RedHatrhoai/odh-mlflow-rhel9:1789653606*
Red Hat OpenShift Dev Spaces 3.30RedHatdevspaces/openvsx-rhel9:1789144269*
Red Hat OpenShift Service Mesh 3.0RedHatopenshift-service-mesh/kiali-ossmc-rhel9:1789023352*
Red Hat OpenShift Service Mesh 3.0RedHatopenshift-service-mesh/kiali-rhel9:1789024827*
Red Hat OpenShift Service Mesh 3.1RedHatopenshift-service-mesh/kiali-ossmc-rhel9:1789023231*
Red Hat OpenShift Service Mesh 3.1RedHatopenshift-service-mesh/kiali-rhel9:1789084585*
Red Hat OpenShift Service Mesh 3.2RedHatopenshift-service-mesh/kiali-ossmc-rhel9:1789021821*
Red Hat OpenShift Service Mesh 3.2RedHatopenshift-service-mesh/kiali-rhel9:1789022173*
Red Hat OpenShift Service Mesh 3.3RedHatopenshift-service-mesh/kiali-ossmc-rhel9:1789050085*
Red Hat OpenShift Service Mesh 3.3RedHatopenshift-service-mesh/kiali-rhel9:1789027395*
Red Hat OpenShift Service Mesh 3.4RedHatopenshift-service-mesh/kiali-ossmc-rhel9:1789475294*
Red Hat OpenShift Service Mesh 3.4RedHatopenshift-service-mesh/kiali-rhel9:1789021319*
Red Hat Quay 3.10RedHatquay/quay-rhel8:1788561841*
Red Hat Quay 3.14RedHatquay/quay-rhel8:1788593843*
Red Hat Quay 3.16RedHatquay/quay-rhel9:1789563753*
Red Hat Satellite 6.18RedHatsatellite/iop-advisor-frontend-rhel9:1789659573*
Red Hat Satellite 6.18RedHatsatellite/iop-remediations-rhel9:1789615095*
Red Hat Satellite 6.19RedHatsatellite/iop-remediations-rhel9:1789615593*
Red Hat Satellite 6.19RedHatsatellite/iop-advisor-frontend-rhel9:1789659565*

Potential Mitigations

  • Mitigation of resource exhaustion attacks requires that the target system either:

  • The first of these solutions is an issue in itself though, since it may allow attackers to prevent the use of the system by a particular valid user. If the attacker impersonates the valid user, they may be able to prevent the user from accessing the server in question.

  • The second solution is simply difficult to effectively institute – and even when properly done, it does not provide a full solution. It simply makes the attack require more resources on the part of the attacker.

References