CVE-2026-84375
Vulnerability Summary
Timeline
Description
js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias a large sequence of empty mappings into many merge targets, causing O(N * K) processing while totalMergeKeys remains unchanged and the configured resource limit is never reached. A relatively small YAML document can therefore cause prolonged CPU consumption in applications that parse untrusted YAML, and merge processing is enabled by default on these release lines. This issue is fixed in versions 3.15.2 and 4.3.2.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- v3.1•HIGH•Score: 8.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
EPSS Trends
Current EPSS score: 0.39%• Percentile: 32%
Techniques & Countermeasures
- CWE-400•Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
- CWE-407•Inefficient Algorithmic Complexity
An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.
Affected Systems
- chainguard•airflow-2
all
- chainguard•airflow-core-2
all
- chainguard•arangodb-3.12
all | < 3.12.9.4-r35
- chainguard•argo-workflows-ui-4.0
< 4.0.11-r0
- chainguard•authentik-2025.12
all
- chainguard•authentik-2026.2
all
- chainguard•authentik-2026.5
all | < 2026.5.7-r1
- chainguard•authentik-fips-2025.12
all | < 2025.12.6-r13
- chainguard•authentik-fips-2026.5
all | < 2026.5.7-r2
- chainguard•awx
all | < 24.6.1-r56
- chainguard•code-server
< 4.136.2-r1
- chainguard•commercial-gitlab-rails-ee-19.1
all
- chainguard•commercial-gitlab-rails-ee-19.2
all
- chainguard•commercial-gitlab-rails-ee-19.3
all
- chainguard•commercial-gitlab-rails-ee-fips-19.1
all
- chainguard•commercial-gitlab-rails-ee-fips-19.2
all
- chainguard•commercial-gitlab-rails-ee-fips-19.3
all
- chainguard•eslint
all | < 10.10.0-r1
- chainguard•foxx-cli
all | < 2.1.1-r11
- chainguard•gitlab-rails-ce-18.10
all
- chainguard•gitlab-rails-ce-18.11
all
- chainguard•gitlab-rails-ce-18.7
all
- chainguard•gitlab-rails-ce-18.8
all
- chainguard•gitlab-rails-ce-18.9
all
- chainguard•gitlab-rails-ce-19.0
all
- chainguard•gitlab-rails-ce-fips-18.10
all
- chainguard•gitlab-rails-ce-fips-18.11
all
- chainguard•gitlab-rails-ce-fips-18.7
all
- chainguard•gitlab-rails-ce-fips-18.8
all
- chainguard•gitlab-rails-ce-fips-18.9
all
- chainguard•gitlab-rails-ce-fips-19.0
all
- chainguard•gitlab-rails-ce-fips-19.1
all | < 19.1.8-r0
- chainguard•jupyter-base-notebook
all
- chainguard•katib-suggestion-hyperopt
< 0.19.0-r40
- chainguard•kibana-8.19
all | < 8.19.21-r2
- chainguard•kibana-8.19-bitnami
all | < 8.19.21-r2
- chainguard•kibana-8.19-iamguarded
all | < 8.19.21-r2
- chainguard•kibana-9.3
all
- chainguard•kibana-9.3-iamguarded
all
- chainguard•lerna
all | < 10.0.1-r3
- chainguard•mongod-7.0-oci-entrypoint-compat
all | < 7.0.41-r1
- chainguard•mongod-8.0-oci-entrypoint-compat
all | < 8.0.32-r1
- chainguard•mongod-8.2-oci-entrypoint-compat
all
- chainguard•mongod-8.3-oci-entrypoint-compat
all | < 8.3.9-r1
- chainguard•opensearch-dashboards-2
all | < 2.19.6-r19
- chainguard•opensearch-dashboards-2-fips
all | < 2.19.6-r8
- chainguard•opensearch-dashboards-3
all | < 3.8.0-r4
- chainguard•opensearch-dashboards-3-fips
all | < 3.8.0-r2
- chainguard•percona-server-mongodb-7.0-oci-entrypoint
all | < 7.0.40_p22-r2
- chainguard•percona-server-mongodb-8.0-oci-entrypoint
all | < 8.0.29.13-r2
Showing first 50 affected entries in server-rendered view.
References (50)
- https://github.com/nodeca/js-yaml/security/advisories/GHSA-2883-xcg3-v3hh
- https://github.com/nodeca/js-yaml/pull/797
- https://github.com/nodeca/js-yaml/commit/3485bc06ff8a0251505f44a00414d90df2466639
- https://github.com/nodeca/js-yaml/commit/6a8e05f9a485188ed730ac81e81ae221352ef480
- https://github.com/nodeca/js-yaml/commit/d90b6612a5a84385bdcb556c44578eac76dc0f6b
- https://github.com/nodeca/js-yaml/releases/tag/3.15.2
- https://github.com/nodeca/js-yaml/releases/tag/4.3.2
- https://security-tracker.debian.org/tracker/CVE-2026-84375
- https://ubuntu.com/security/CVE-2026-84375
- https://www.cve.org/CVERecord?id=CVE-2026-84375
- https://access.redhat.com/errata/RHSA-2026:62810
- https://access.redhat.com/security/cve/CVE-2026-84375
- https://access.redhat.com/security/updates/classification/
- https://images.redhat.com/
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_62810.json
- https://bugzilla.redhat.com/show_bug.cgi?id=2527118
- https://nvd.nist.gov/vuln/detail/CVE-2026-84375
- https://access.redhat.com/errata/RHSA-2026:62813
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_62813.json
- https://access.redhat.com/errata/RHSA-2026:63165
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_63165.json
- https://access.redhat.com/security/cve/CVE-2026-17033
- https://access.redhat.com/security/cve/CVE-2026-19197
- https://github.com/nodeca/js-yaml
- https://access.redhat.com/security/cve/CVE-2026-21723
- https://access.redhat.com/security/cve/CVE-2026-9765
- https://access.redhat.com/security/cve/CVE-2026-8595
- https://access.redhat.com/security/cve/CVE-2026-33382
- https://access.redhat.com/security/cve/CVE-2026-8609
- https://bugzilla.redhat.com/show_bug.cgi?id=2499051
- https://www.cve.org/CVERecord?id=CVE-2026-8595
- https://nvd.nist.gov/vuln/detail/CVE-2026-8595
- https://grafana.com/security/security-advisories/cve-2026-8595
- https://bugzilla.redhat.com/show_bug.cgi?id=2499061
- https://www.cve.org/CVERecord?id=CVE-2026-8609
- https://nvd.nist.gov/vuln/detail/CVE-2026-8609
- https://grafana.com/security/security-advisories/cve-2026-8609
- https://bugzilla.redhat.com/show_bug.cgi?id=2506730
- https://www.cve.org/CVERecord?id=CVE-2026-9765
- https://nvd.nist.gov/vuln/detail/CVE-2026-9765
- https://grafana.com/security/security-advisories/cve-2026-9765
- https://bugzilla.redhat.com/show_bug.cgi?id=2506342
- https://www.cve.org/CVERecord?id=CVE-2026-21723
- https://nvd.nist.gov/vuln/detail/CVE-2026-21723
- https://grafana.com/security/security-advisories/cve-2026-21723
- https://bugzilla.redhat.com/show_bug.cgi?id=2499062
- https://www.cve.org/CVERecord?id=CVE-2026-33382
- https://nvd.nist.gov/vuln/detail/CVE-2026-33382
- https://grafana.com/security/security-advisories/cve-2026-33382
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84375.json