CVE-2026-84375
Last modified
CVE-2026-84375 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias a large sequence of empty mappings into many merge targets, causing O(N * K) processing while totalMergeKeys remains unchanged and the configured resource limit is never reached. A relatively small YAML document can therefore cause prolonged CPU consumption in applications that parse untrusted YAML, and merge processing is enabled by default on these release lines. This issue is fixed in versions 3.15.2 and 4.3.2.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| nodeca | js-yaml | >= 3.0.0, < 3.15.2; >= 4.0.0, < 4.3.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-84375?
How severe is CVE-2026-84375?
How do I fix CVE-2026-84375?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-84369SVGO, short for SVG Optimizer, is a Node.js library and comm…6.1
- CVE-2026-84370SVGO, short for SVG Optimizer, is a Node.js library and comm…8.2
- CVE-2026-84371ApostropheCMS is an open-source Node.js content management s…5.4
- CVE-2026-84372Predis is a flexible and feature-complete Redis and Valkey c…9.8
- CVE-2026-84373Vitest is a testing framework powered by Vite. From 2.1.0 un…5.9
- CVE-2026-84374Laravel Excel provides supercharged Excel exports and import…7.5
- CVE-2026-84376Astro is a web framework for content-driven websites. Prior …6.3
- CVE-2026-84377LiteLLM is a proxy server (AI Gateway) to call LLM APIs in O…6.5
- CVE-2026-84378HTTPX2 is a next generation HTTP client for Python. From 2.5…5.9
- CVE-2026-84379HTTPX2 is a next generation HTTP client for Python. Prior to…5.3
- CVE-2026-8438The All-In-One Security (AIOS) – Security and Firewall plugi…7.2
- CVE-2026-84380HTTPX2 is a next generation HTTP client for Python. Prior to…5.6
Are you affected by CVE-2026-84375?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
