Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
"yauzl" is only mentioned in a few lockfiles, not otherwise present in the source tarball, and none of that is used in the build nor shipped in the resulting packages.