Bug 2515531 (CVE-2026-73643)
| Summary: | CVE-2026-73643 js-yaml: js-yaml: Denial of Service via exponential parsing in flow collections | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | aadhikar, aazores, abarbaro, abuckta, akostadi, alizardo, amasferr, amctagga, anjoseph, anpicker, anthomas, anujha, aoconnor, aruklets, aschwart, asoldano, aszczucz, ataylor, bbaranow, bbrownin, bmaxwell, bniver, boliveir, bparees, brasmith, bsmejkal, bstansbe, cdrage, cmah, cochase, dbosanac, dbruscin, dfreiber, dkeler, dkuc, dlofthou, dmayorov, doconnor, dranck, drichtar, drow, dschmidt, dymurray, eaguilar, ebaron, eborisov, ehelms, ehugonne, ewittman, flucifre, fmariani, ggainey, gmalinko, gmeno, gotiwari, gparvin, groman, hasun, ibolton, istudens, ivassile, iweiss, jachapma, janstey, jburrell, jchui, jfula, jhe, jhorak, jlanda, jlledo, jmatsuok, jmatthew, jmontleo, jowilson, jpasqual, jprabhak, jreimann, jtolenti, juwatts, jwong, jwon, kaycoth, kshier, ktsao, kvanderr, lball, lchilton, mbarnett, mbenjamin, mcarlett, mdellweg, mdessi, mhackett, mhulan, mosmerov, mposolda, mreynolds, mrizzi, mstipich, msvehla, mvyas, nboldt, ngough, nipatil, nmoumoul, nwallace, nyancey, oaljalju, omaciel, ometelka, orabin, osousa, pantinor, pberan, pcattana, pcreech, pesilva, pgaikwad, pjindal, pmackay, progier, psrna, ptisnovs, rchan, rexwhite, rhaigner, rhel-process-autobot, rjohnson, rkubis, rmartinc, rstancel, rstepani, rushinde, sdawley, sfeifer, simaishi, slucidi, smallamp, snegrini, sostapov, spichugi, sseago, ssilvert, stcannon, sthirugn, sthorger, suppawar, syedriko, tbordaz, tcunning, teagle, thason, thjenkin, tmalecek, tsedmik, ttakamiy, vashirov, vdosoudi, vereddy, veshanka, vkumar, vmuzikar, watson-tool-maintainers, wtam, xdharmai, yfang, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in js-yaml, a JavaScript YAML parser. A remote attacker could exploit this vulnerability by providing specially crafted YAML input containing nested flow collections. This can lead to exponential parsing time when the application processes untrusted input, consuming excessive CPU resources. This resource exhaustion can block the Node.js event loop and cause a Denial of Service (DoS) for the affected process.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-13 18:27:16 UTC
|