VendorsNodecajs-yamlany version
Vulnerabilities

Nodeca JS-YAML any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2026-59868
js-yaml: YAML merge-key chains can force quadratic CPU consumption
Published 2026-07-08 · Analyzed
7.5EPSS 0.006
CVE-2026-59870
js-yaml quadratic-complexity denial of service via YAML11_SCHEMA !!omap parsing
Published 2026-07-08 · Analyzed
7.5EPSS 0.006
CVE-2026-59869
js-yaml: YAML merge-key chains can force quadratic CPU consumption
Published 2026-07-08 · Analyzed
7.5EPSS 0.006
CVE-2013-4660
The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attackers to execute arbitrary code via a crafted string that triggers an eval operation.
Published 2013-06-28 · Modified
6.81 PoCEPSS 0.173
CVE-2026-53550
js-yaml: Quadratic-complexity DoS in merge key handling via repeated aliases
Published 2026-06-22 · Analyzed
5.3EPSS 0.004
CVE-2025-64718
js-yaml has prototype pollution in merge (<<)
Published 2025-11-13 · Analyzed
5.3EPSS 0.004