CVE-2026-73643: js-yaml: Exponential parsing time in the flow collections leads to denial of service
js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2, parsing a small YAML document can take exponential time when an application calls load() or loadAll() on untrusted input. In src/parser/parser.ts, readFlowCollection uses restoreState and calls parseNode a second time when a flow-sequence entry is recognized as a key: value pair. If the key is a nested flow sequence of the same shape, every level is parsed twice, causing O(2^n) work and allowing an input under 200 bytes to keep one CPU busy for minutes, block the Node.js event loop, and stall the process. No anchors, aliases, merges, tags, or nondefault options are required. This issue is fixed in version 5.2.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
js-yamlto a version that resolves this vulnerability.Fixed in 5.2.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73643?
The severity of CVE-2026-73643 is rated high with a CVSS score of 7.5.
How do I fix CVE-2026-73643?
To mitigate CVE-2026-73643, upgrade js-yaml to version 5.2.3 or later.
What is the impact of CVE-2026-73643?
CVE-2026-73643 can lead to a denial of service due to exponential parsing time on untrusted YAML input.
Which versions of js-yaml are affected by CVE-2026-73643?
CVE-2026-73643 affects js-yaml versions from 5.0.0 to 5.2.2.
What functionality in js-yaml is vulnerable in CVE-2026-73643?
The vulnerability in CVE-2026-73643 is due to the behavior of the load() and loadAll() functions when processing untrusted input.