PatchSiren cyber security CVE debrief
CVE-2026-84375 nodeca CVE debrief
CVE-2026-84375 is a high-severity vulnerability in the js-yaml library, affecting versions from 3.0.0 to 3.15.2, 4.3.2, and 5.4.1. The vulnerability occurs due to the maxTotalMergeKeys function not counting empty mapping sources while processing the merge key <<. This allows an attacker to alias a large sequence of empty mappings into many merge targets, causing O(N * K) processing while totalMergeKeys remains unchanged and the configured resource limit is never reached. A relatively small YAML document can therefore cause prolonged CPU consumption in applications that parse untrusted YAML, and merge processing is enabled by default on these release lines.
- Vendor
- nodeca
- Product
- js-yaml
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-01
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-01
- Advisory updated
- 2026-09-28
Who should care
Defenders responsible for systems that use js-yaml to parse untrusted YAML should assess exposure and prioritize upgrading to fixed versions. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify affected versions, assess exposure, and monitor for unusual CPU consumption in applications that use js-yaml.
Why it matters
CVE-2026-84375 is a high-severity vulnerability in js-yaml that can cause prolonged CPU consumption in applications that parse untrusted YAML. Defenders should prioritize upgrading to fixed versions and assess exposure in systems that use js-yaml.
- Prolonged CPU consumption in applications that parse untrusted YAML
- Potential for denial-of-service (DoS) attacks
- Need for verification of affected versions and exposure
Technical summary
The js-yaml library has a vulnerability that allows an attacker to cause prolonged CPU consumption by aliasing a large sequence of empty mappings into many merge targets. This occurs due to the maxTotalMergeKeys function not counting empty mapping sources while processing the merge key <<. The vulnerability affects versions from 3.0.0 to 3.15.2, 4.3.2, and 5.4.1. Defenders should prioritize upgrading to fixed versions and assess exposure in systems that use js-yaml to parse untrusted YAML. The vulnerability can cause O(N * K) processing while totalMergeKeys remains unchanged and the configured resource limit is never reached. A relatively small YAML document can therefore cause prolonged CPU consumption in
Defensive priority
Defenders should prioritize upgrading to fixed versions 3.15.2, 4.3.2, or 5.4.1, and assess exposure in systems that use js-yaml to parse untrusted YAML.
Recommended defensive actions
- Upgrade to js-yaml version 3.15.2, 4.3.2, or 5.4.1
- Assess exposure in systems that use js-yaml to parse untrusted YAML
- Monitor for unusual CPU consumption in applications that use js-yaml
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, affected versions, and fixed versions. However, there is no information on known exploitation or victims. Defenders should verify affected versions, assess exposure, and monitor for unusual CPU consumption in applications that use js-yaml. The vulnerability allows an attacker to cause prolonged CPU consumption by aliasing a large sequence of empty mappings into many merge targets. This occurs due to the maxTotalMergeKeys function not counting empty mapping sources. The
Sources and references
Verified primary and authoritative sources
-
CVE-2026-84375 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-84375
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-84375 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84375
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/nodeca/js-yaml/commit/3485bc06ff8a0251505f44a00414d90df2466639
-
Source reference
Unverified legacy reference
URL: https://github.com/nodeca/js-yaml/commit/6a8e05f9a485188ed730ac81e81ae221352ef480
-
Source reference
Unverified legacy reference
URL: https://github.com/nodeca/js-yaml/commit/d90b6612a5a84385bdcb556c44578eac76dc0f6b
-
Source reference
Unverified legacy reference
URL: https://github.com/nodeca/js-yaml/pull/797
-
Source reference
Unverified legacy reference
URL: https://github.com/nodeca/js-yaml/releases/tag/3.15.2
-
Source reference
Unverified legacy reference
URL: https://github.com/nodeca/js-yaml/releases/tag/4.3.2
-
Source reference
Unverified legacy reference
URL: https://github.com/nodeca/js-yaml/releases/tag/5.4.1
-
Source reference
Unverified legacy reference
URL: https://github.com/nodeca/js-yaml/security/advisories/GHSA-2883-xcg3-v3hh
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.