REDHAT-BUG-2515531: High severity npm/js-yaml vulnerability
js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2, parsing a small YAML document can take exponential time when an application calls load() or loadAll() on untrusted input. In src/parser/parser.ts, readFlowCollection uses restoreState and calls parseNode a second time when a flow-sequence entry is recognized as a key: value pair. If the key is a nested flow sequence of the same shape, every level is parsed twice, causing O(2^n) work and allowing an input under 200 bytes to keep one CPU busy for minutes, block the Node.js event loop, and stall the process. No anchors, aliases, merges, tags, or nondefault options are required. This issue is fixed in version 5.2.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
js-yamlto a version that resolves this vulnerability.Fixed in 5.2.2
Event History
Frequently Asked Questions
Who is exposed to this issue?
Applications using npm/js-yaml versions from 5.0.0 through 5.2.1 are exposed if they call load() or loadAll() on YAML supplied by an untrusted source. A successful attack can monopolize CPU time, block the Node.js event loop, and stall the process.
Does exploitation require special YAML features or nondefault parser settings?
No. The issue can be triggered with a small YAML document using nested flow sequences; anchors, aliases, merges, tags, and nondefault options are not required.
What should be done if the application parses untrusted YAML?
Upgrade js-yaml to version 5.2.2, which fixes the issue. Until upgrading is possible, avoid passing untrusted YAML to load() or loadAll().
How can I determine whether an application is affected?
Check whether the application depends on npm/js-yaml and uses version 5.0.0, 5.0.1, 5.1.0, or 5.2.1. Then identify whether any code path calls load() or loadAll() with attacker-controlled or otherwise untrusted YAML input.