CVE-2025-9308: yarnpkg Yarn request-manager.js setOptions redos
A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/request-manager.js. Such manipulation leads to inefficient regular expression complexity. Local access is required to approach this attack. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9308?
CVE-2025-9308 is classified as a medium severity vulnerability due to its potential to lead to inefficient regular expression complexity.
How do I fix CVE-2025-9308?
To mitigate CVE-2025-9308, update Yarn to version 1.22.23 or later, which addresses the vulnerability.
What kind of access is required to exploit CVE-2025-9308?
Local access is required to exploit CVE-2025-9308, as it cannot be triggered remotely.
What impact does CVE-2025-9308 have on applications?
CVE-2025-9308 can lead to performance issues due to inefficient regular expression evaluation in affected applications.
Which versions of Yarn are affected by CVE-2025-9308?
Yarn versions up to 1.22.22 are affected by CVE-2025-9308.