REDHAT-BUG-2515531: High severity npm/js-yaml vulnerability

Published Aug 13, 2026
·
Updated

js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2, parsing a small YAML document can take exponential time when an application calls load() or loadAll() on untrusted input. In src/parser/parser.ts, readFlowCollection uses restoreState and calls parseNode a second time when a flow-sequence entry is recognized as a key: value pair. If the key is a nested flow sequence of the same shape, every level is parsed twice, causing O(2^n) work and allowing an input under 200 bytes to keep one CPU busy for minutes, block the Node.js event loop, and stall the process. No anchors, aliases, merges, tags, or nondefault options are required. This issue is fixed in version 5.2.2.

Affected Software

1 affected component
npm/js-yaml>=5.0.0<=5.2.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade js-yaml to a version that resolves this vulnerability.

    Fixed in 5.2.2

Event History

Aug 13, 2026
Data Sourced
via Red Hat·06:27 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using npm/js-yaml versions from 5.0.0 through 5.2.1 are exposed if they call load() or loadAll() on YAML supplied by an untrusted source. A successful attack can monopolize CPU time, block the Node.js event loop, and stall the process.

2

Does exploitation require special YAML features or nondefault parser settings?

No. The issue can be triggered with a small YAML document using nested flow sequences; anchors, aliases, merges, tags, and nondefault options are not required.

3

What should be done if the application parses untrusted YAML?

Upgrade js-yaml to version 5.2.2, which fixes the issue. Until upgrading is possible, avoid passing untrusted YAML to load() or loadAll().

4

How can I determine whether an application is affected?

Check whether the application depends on npm/js-yaml and uses version 5.0.0, 5.0.1, 5.1.0, or 5.2.1. Then identify whether any code path calls load() or loadAll() with attacker-controlled or otherwise untrusted YAML input.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203