CVE-2026-73643: js-yaml: Exponential parsing time in the flow collections leads to denial of service

Published Aug 13, 2026
·
Updated

js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2, parsing a small YAML document can take exponential time when an application calls load() or loadAll() on untrusted input. In src/parser/parser.ts, readFlowCollection uses restoreState and calls parseNode a second time when a flow-sequence entry is recognized as a key: value pair. If the key is a nested flow sequence of the same shape, every level is parsed twice, causing O(2^n) work and allowing an input under 200 bytes to keep one CPU busy for minutes, block the Node.js event loop, and stall the process. No anchors, aliases, merges, tags, or nondefault options are required. This issue is fixed in version 5.2.2.

Affected Software

1 affected component
npm/js-yaml>=5.0.0<=5.2.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade js-yaml to a version that resolves this vulnerability.

    Fixed in 5.2.2

Event History

Aug 13, 2026
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·06:27 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-73643?

The severity of CVE-2026-73643 is rated high with a CVSS score of 7.5.

2

How do I fix CVE-2026-73643?

To mitigate CVE-2026-73643, upgrade js-yaml to version 5.2.3 or later.

3

What is the impact of CVE-2026-73643?

CVE-2026-73643 can lead to a denial of service due to exponential parsing time on untrusted YAML input.

4

Which versions of js-yaml are affected by CVE-2026-73643?

CVE-2026-73643 affects js-yaml versions from 5.0.0 to 5.2.2.

5

What functionality in js-yaml is vulnerable in CVE-2026-73643?

The vulnerability in CVE-2026-73643 is due to the behavior of the load() and loadAll() functions when processing untrusted input.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203