Vulnerabilities |
2 via 2 paths |
|---|---|
Dependencies |
171 |
Source |
GitHub |
Find, fix and prevent vulnerabilities in your code.
high severity
- Vulnerable module: js-yaml
- Introduced through: js-yaml@4.2.0
Detailed paths
-
Introduced through: kastell@kastelldev/kastell › js-yaml@4.2.0Remediation: Upgrade to js-yaml@4.3.0.
Overview
js-yaml is a human-friendly data serialization language.
Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity in merge key (<<) handling during YAML parsing, where each mapping in a chain re-enumerates the keys inherited from the previous mapping. An attacker can exhaust CPU and cause denial of service by supplying a document with N chained merge mappings, which forces roughly O(N^2) work for O(N) input. Exploitation requires the application to parse untrusted YAML with the default or YAML11 schema, under which merge keys are resolved.
Remediation
Upgrade js-yaml to version 3.15.0, 4.3.0 or higher.
References
high severity
new
- Vulnerable module: js-yaml
- Introduced through: js-yaml@4.2.0
Detailed paths
-
Introduced through: kastell@kastelldev/kastell › js-yaml@4.2.0Remediation: Upgrade to js-yaml@4.3.1.
Overview
js-yaml is a human-friendly data serialization language.
Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity through the yaml.load process. An attacker can cause excessive CPU consumption and block the event loop by providing a specially crafted YAML document containing a large !!omap sequence.
Remediation
Upgrade js-yaml to version 3.15.1, 4.3.1 or higher.