js-yaml
HighnpmCVE-2026-84375
What to do
Update js-yaml to 4.3.2 or later.
npm install js-yaml@4.3.2
A denial of service flaw affects the npm package js-yaml. Affected versions: >= 4.0.0, < 4.3.2. Fixed from version 4.3.2. CVSS score 7.5.
What the flaw allows: The service can be knocked over cheaply.
- Package
- js-yaml
- Ecosystem
- npm (JavaScript)
- Class
- Denial of service
- Affected versions
- >= 4.0.0, < 4.3.2
- CVSS
- 7.5
- Published on
- September 8, 2026
Sources
Entry built automatically from the cited security advisory, with no model rewriting. Acknowledged by the organisation or vendor, notified to an authority, or established by two independent sources.