Bug 2515531 (CVE-2026-73643)

Summary: CVE-2026-73643 js-yaml: js-yaml: Denial of Service via exponential parsing in flow collections
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aadhikar, aazores, abarbaro, abuckta, akostadi, alizardo, amasferr, amctagga, anjoseph, anpicker, anthomas, anujha, aoconnor, aruklets, aschwart, asoldano, aszczucz, ataylor, bbaranow, bbrownin, bmaxwell, bniver, boliveir, bparees, brasmith, bsmejkal, bstansbe, cdrage, cmah, cochase, dbosanac, dbruscin, dfreiber, dkeler, dkuc, dlofthou, dmayorov, doconnor, dranck, drichtar, drow, dschmidt, dymurray, eaguilar, ebaron, eborisov, ehelms, ehugonne, ewittman, flucifre, fmariani, ggainey, gmalinko, gmeno, gotiwari, gparvin, groman, hasun, ibolton, istudens, ivassile, iweiss, jachapma, janstey, jburrell, jchui, jfula, jhe, jhorak, jlanda, jlledo, jmatsuok, jmatthew, jmontleo, jowilson, jpasqual, jprabhak, jreimann, jtolenti, juwatts, jwong, jwon, kaycoth, kshier, ktsao, kvanderr, lball, lchilton, mbarnett, mbenjamin, mcarlett, mdellweg, mdessi, mhackett, mhulan, mosmerov, mposolda, mreynolds, mrizzi, mstipich, msvehla, mvyas, nboldt, ngough, nipatil, nmoumoul, nwallace, nyancey, oaljalju, omaciel, ometelka, orabin, osousa, pantinor, pberan, pcattana, pcreech, pesilva, pgaikwad, pjindal, pmackay, progier, psrna, ptisnovs, rchan, rexwhite, rhaigner, rhel-process-autobot, rjohnson, rkubis, rmartinc, rstancel, rstepani, rushinde, sdawley, sfeifer, simaishi, slucidi, smallamp, snegrini, sostapov, spichugi, sseago, ssilvert, stcannon, sthirugn, sthorger, suppawar, syedriko, tbordaz, tcunning, teagle, thason, thjenkin, tmalecek, tsedmik, ttakamiy, vashirov, vdosoudi, vereddy, veshanka, vkumar, vmuzikar, watson-tool-maintainers, wtam, xdharmai, yfang, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in js-yaml, a JavaScript YAML parser. A remote attacker could exploit this vulnerability by providing specially crafted YAML input containing nested flow collections. This can lead to exponential parsing time when the application processes untrusted input, consuming excessive CPU resources. This resource exhaustion can block the Node.js event loop and cause a Denial of Service (DoS) for the affected process.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-13 18:27:16 UTC
js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2, parsing a small YAML document can take exponential time when an application calls load() or loadAll() on untrusted input. In src/parser/parser.ts, readFlowCollection uses restoreState and calls parseNode a second time when a flow-sequence entry is recognized as a key: value pair. If the key is a nested flow sequence of the same shape, every level is parsed twice, causing O(2^n) work and allowing an input under 200 bytes to keep one CPU busy for minutes, block the Node.js event loop, and stall the process. No anchors, aliases, merges, tags, or nondefault options are required. This issue is fixed in version 5.2.2.