{"id":"CVE-2026-59869","aliases":["GHSA-52cp-r559-cp3m"],"url":"https://o3.security/vulnerability/CVE-2026-59869","summary":"js-yaml: YAML merge-key chains can force quadratic CPU consumption","details":"js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.","published":"2026-07-08T15:15:54.675Z","modified":"2026-08-12T03:51:40.403634755Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"js-yaml","fixedVersion":"3.15.0"},{"ecosystem":"npm","name":"js-yaml","fixedVersion":"4.3.0"}],"fix":{"url":"https://github.com/nodeca/js-yaml/commit/24f13e79ee1343a7e30bd6f6c9d9cdbf0ac9b2b7","label":"nodeca/js-yaml@24f13e7"},"references":[{"type":"WEB","url":"https://github.com/nodeca/js-yaml/releases/tag/3.15.0"},{"type":"WEB","url":"https://github.com/nodeca/js-yaml/releases/tag/4.3.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59869.json"},{"type":"ADVISORY","url":"https://github.com/nodeca/js-yaml/security/advisories/GHSA-52cp-r559-cp3m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59869"},{"type":"FIX","url":"https://github.com/nodeca/js-yaml/commit/24f13e79ee1343a7e30bd6f6c9d9cdbf0ac9b2b7"},{"type":"FIX","url":"https://github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e4"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:40.403634755Z"}}