PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84375 nodeca CVE debrief

CVE-2026-84375 is a high-severity vulnerability in the js-yaml library, affecting versions from 3.0.0 to 3.15.2, 4.3.2, and 5.4.1. The vulnerability occurs due to the maxTotalMergeKeys function not counting empty mapping sources while processing the merge key <<. This allows an attacker to alias a large sequence of empty mappings into many merge targets, causing O(N * K) processing while totalMergeKeys remains unchanged and the configured resource limit is never reached. A relatively small YAML document can therefore cause prolonged CPU consumption in applications that parse untrusted YAML, and merge processing is enabled by default on these release lines.

Vendor
nodeca
Product
js-yaml
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-01
Original CVE updated
2026-09-28
Advisory published
2026-09-01
Advisory updated
2026-09-28

Who should care

Defenders responsible for systems that use js-yaml to parse untrusted YAML should assess exposure and prioritize upgrading to fixed versions. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify affected versions, assess exposure, and monitor for unusual CPU consumption in applications that use js-yaml.

Why it matters

CVE-2026-84375 is a high-severity vulnerability in js-yaml that can cause prolonged CPU consumption in applications that parse untrusted YAML. Defenders should prioritize upgrading to fixed versions and assess exposure in systems that use js-yaml.

  • Prolonged CPU consumption in applications that parse untrusted YAML
  • Potential for denial-of-service (DoS) attacks
  • Need for verification of affected versions and exposure

Technical summary

The js-yaml library has a vulnerability that allows an attacker to cause prolonged CPU consumption by aliasing a large sequence of empty mappings into many merge targets. This occurs due to the maxTotalMergeKeys function not counting empty mapping sources while processing the merge key <<. The vulnerability affects versions from 3.0.0 to 3.15.2, 4.3.2, and 5.4.1. Defenders should prioritize upgrading to fixed versions and assess exposure in systems that use js-yaml to parse untrusted YAML. The vulnerability can cause O(N * K) processing while totalMergeKeys remains unchanged and the configured resource limit is never reached. A relatively small YAML document can therefore cause prolonged CPU consumption in

Defensive priority

Defenders should prioritize upgrading to fixed versions 3.15.2, 4.3.2, or 5.4.1, and assess exposure in systems that use js-yaml to parse untrusted YAML.

Recommended defensive actions

  • Upgrade to js-yaml version 3.15.2, 4.3.2, or 5.4.1
  • Assess exposure in systems that use js-yaml to parse untrusted YAML
  • Monitor for unusual CPU consumption in applications that use js-yaml
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, affected versions, and fixed versions. However, there is no information on known exploitation or victims. Defenders should verify affected versions, assess exposure, and monitor for unusual CPU consumption in applications that use js-yaml. The vulnerability allows an attacker to cause prolonged CPU consumption by aliasing a large sequence of empty mappings into many merge targets. This occurs due to the maxTotalMergeKeys function not counting empty mapping sources. The

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84375 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84375

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84375 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84375

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.