Bug 2390129 (CVE-2025-9308)

Summary: CVE-2025-9308 yarn: yarnpkg regular expression denial of service
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: anjoseph, bdettelb, caswilli, doconnor, jprabhak, jwendell, kaycoth, kbempah, lchilton, manisandro, rcernich, rhel-process-autobot, sfeifer, solenoci, teagle, watson-tool-maintainers, wtam
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A regular expression denial of service flaw has been found in the `yarn` npm module. An attacker with local access can manipulate input to the function `setOptions` in such a way that the yarnpkg program becomes unresponsive.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2390167, 2390168, 2390169, 2390170, 2390171    
Bug Blocks:    

Description OSIDB Bzimport 2025-08-21 17:01:42 UTC
A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/request-manager.js. Such manipulation leads to inefficient regular expression complexity. Local access is required to approach this attack. This vulnerability only affects products that are no longer supported by the maintainer.

Comment 2 Sandro Mani 2025-12-13 09:21:01 UTC
This looks the same as CVE-2025-8262, which was already fixed in yarnpkg-1.22.22-11