CVE-2026-84375

Aliases:DEBIAN-CVE-2026-84375UBUNTU-CVE-2026-84375RHSA-2026:62810RHSA-2026:62813RHSA-2026:63165GHSA-2883-xcg3-v3hhCGA-3xqh-3qvx-r885CGA-4c33-fhv5-wm8xCGA-8v5w-wc8j-cg53CGA-9rr9-g282-4cw5CGA-fff5-hvq2-qwc5CGA-pc73-73jj-w7h2CGA-rc5c-q73x-5mwwCGA-rc76-5mpv-rw9wCGA-vrr6-m3mq-8xr9CGA-xwmh-xhm7-hcrcCGA-2659-hr44-jjf2CGA-26xr-q2h5-3r9jCGA-2fcq-wx89-hpghCGA-2qp7-rmgc-vq29CGA-2wpm-fv59-3g93CGA-2xm5-83gp-79pqCGA-35h4-568x-f83rCGA-3643-8hp9-p2fxCGA-3jv6-2gmv-c3r4CGA-3x22-xccj-xp24CGA-48gc-5jjq-562jCGA-4f7x-wphp-g9x2CGA-4mfc-xhgg-r346CGA-4wch-m6fr-9g73CGA-5cjc-rvmx-3p5rCGA-5f2r-rv23-pw89CGA-5gw8-346m-rpqfCGA-5p5c-hf28-v875CGA-5pw2-f4wj-2hjjCGA-63q7-ghqp-794hCGA-6824-qc83-c37cCGA-68mm-9q4v-23j2CGA-6h3m-xhw8-pc46CGA-6mgr-ghg8-883fCGA-6p6f-q4qh-f63qCGA-6rcw-gwhx-8559CGA-6wgr-99f2-vrgjCGA-6xqc-mc2g-83m3CGA-7cpr-p722-8gr2CGA-7ffc-4mmr-3g6cCGA-7fvj-x66c-jp3gCGA-7rf5-fjff-cmf8CGA-7rmh-24xq-2j5gCGA-7vxv-24fx-97gwCGA-7w95-2gvh-33r6CGA-8g8w-5rv5-qp8xCGA-9fvr-f4pg-hqw3CGA-9qrp-4gw2-g935CGA-cf68-wc28-c892CGA-cm5v-qh26-2p8fCGA-crwg-p38j-56r5CGA-f939-4pfc-hv6qCGA-fhh8-cfvx-hjcqCGA-fmcr-x45p-923rCGA-frhx-fj73-fjpgCGA-frwr-6w8x-97m4CGA-gcwj-q8q7-5rr7CGA-gh6g-j2hx-qxfrCGA-gx3q-656x-6qqwCGA-hf5m-829q-mffmCGA-hgqx-j226-xfjjCGA-hgr9-q8p4-pgq5CGA-hp4c-4h27-wg73CGA-hxqc-2w44-h4rxCGA-jc6m-g5hh-r79rCGA-jpj5-f2q5-cq97CGA-jqv2-hmhh-j922CGA-jvx8-g4g2-8c2qCGA-mc9r-4fgg-v5grCGA-mhgf-px58-cvv3CGA-mj5r-rvfj-96j7CGA-mw76-h8g4-45cwCGA-p97q-7jrc-2c89CGA-pc2r-45p8-3w64CGA-pch4-978g-rgxrCGA-pfrv-jqj4-wfgcCGA-pm5p-f3wf-75x7CGA-prvm-c9pp-j46gCGA-pv25-4g2c-mw8hCGA-pwfc-xwwm-hx2qCGA-q9gh-878x-26vvCGA-q9p6-rr28-g764CGA-qvr4-xp39-wf95CGA-qw3p-c54x-9hfmCGA-qxq9-x68q-rpjwCGA-rfpx-9r7h-cgx9CGA-rh27-g36c-2gm4CGA-rj9q-9cmc-786vCGA-rpfq-c2w6-rf89CGA-rqh9-jmqj-9g44CGA-rqm2-mp24-fcfxCGA-rr29-69hv-w822CGA-rw65-p6jg-3v68CGA-vjhv-xh2r-wrhmCGA-vp28-f2vv-xp8wCGA-vv7g-mmq9-q7rfCGA-vw34-88mh-hv49CGA-wf2m-679w-qpgfCGA-whcm-cf9q-hp3qCGA-wj2x-g8gg-j85fCGA-wq8v-87hx-9p88CGA-wqcj-w339-wr6rCGA-wvp3-g32p-58xvCGA-xcgq-2p45-xw82CGA-xgvw-9wgq-78pcCGA-xm52-mf5r-3r69CGA-xpv8-x8jh-3qxpCGA-xxpv-2jhg-37wmCGA-5v7r-4fhx-6xrxCGA-qm87-fg2g-hjxhCGA-vq83-339m-4rqqCGA-xvh2-mrfp-mpgwCGA-fgm6-4hqr-jrm9CGA-r29q-xchp-68h3CGA-w367-79c3-6p93CGA-w75r-x545-9rppCGA-2vfp-cxh4-5v4mCGA-2p28-4r4m-j9gqCGA-3969-78wh-jh63CGA-56q9-wjmx-3g47CGA-6qfh-xcvq-6mjcCGA-7gjm-2hgg-jgqwCGA-969h-38pm-37wcCGA-98q8-4j3r-54c3CGA-9vx7-4hc4-mwr3CGA-c8q2-642g-67m2CGA-f2m7-w4vj-mwrpCGA-hr45-2x58-4f5gCGA-m2jx-7r6j-fwmrCGA-mgjh-2mx7-hg2vCGA-mwq4-g5w3-8c64CGA-pg4p-33mc-2w3gCGA-qgrc-c5hw-7r5jCGA-vjxv-qff9-vww4CGA-wvwv-cppq-9h74CGA-x686-8m4p-pwh7CGA-j8gf-f4c2-43ccCGA-285x-pwcc-732cCGA-45f2-fmqc-3vj3CGA-56m3-97v5-29c7CGA-6xmv-9v74-fqg7CGA-73cx-774r-2c87CGA-7784-x9h8-8cv7CGA-77gx-2v9q-rfmhCGA-82h8-xmrq-rv5xCGA-8393-44m3-7p67CGA-976f-jfp9-qgxmCGA-f645-2r8v-mqwmCGA-ffcm-ggrw-hw29CGA-g3v2-mrjc-4xvpCGA-g65m-fpj9-h77fCGA-h47v-w4qr-5352CGA-h4g4-p4w9-84w7CGA-h4v4-9wfr-f4vxCGA-h8vr-6xp2-9ccrCGA-j2qp-3jrq-m6p8CGA-j57h-hc55-m5x9CGA-j8g3-g3hv-c88fCGA-p2jg-4h5v-8wcwCGA-p7w8-m58c-28h5CGA-q4gh-wcfc-jrfwCGA-r388-qw2p-jwcfCGA-r642-pvwv-35q6CGA-v345-7qg3-rcr2CGA-w2pw-5qwf-wvfqCGA-w2qg-cfhp-4xm4CGA-w445-g576-qhw8CGA-x7vq-25w7-v9gvCGA-m79x-866p-ggc4CGA-p6rm-2xw8-g92vCGA-r52c-hf4c-c89qCGA-32wv-w6j8-8mchCGA-654j-q82x-vj93CGA-73fx-m23v-qr5hCGA-c6qg-5m75-gvpfCGA-g5qc-83xx-w2wwCGA-h48x-7r7x-964jCGA-p5m2-fff6-fjwqCGA-r226-2rg9-9grcCGA-r2mv-vw5v-mjjwCGA-432r-m5q4-7w9qCGA-7268-82pv-6fc8CGA-87pw-35hv-vf5xCGA-95mv-4hh4-qpphCGA-j559-mrf5-q59xCGA-p24f-8wcr-wgvhCGA-v3x7-r5w8-qpf3CGA-x34j-3qjp-5qhgCGA-775v-vgwc-rv66CGA-gq66-9wfg-r2c2CGA-j5j8-gfgj-xvhwCGA-jh9r-4mv7-ph6pCGA-v8vw-j96g-3r6qCGA-xr77-37wf-8rrxCGA-82gh-x274-r88vCGA-p5wp-crv6-p2xmCGA-5288-f695-87qcCGA-66hv-vc69-58cx
Advisory lineage Upstream: 5 Downstream: 1
Deferred
Published: 01 Sept 2026, 21:43
Last modified:02 Sept 2026, 16:02

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.39% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 Sept 2026, 21:43
Published
Vulnerability first disclosed
02 Sept 2026, 16:02
Last Modified
Vulnerability information updated

Description

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias a large sequence of empty mappings into many merge targets, causing O(N * K) processing while totalMergeKeys remains unchanged and the configured resource limit is never reached. A relatively small YAML document can therefore cause prolonged CPU consumption in applications that parse untrusted YAML, and merge processing is enabled by default on these release lines. This issue is fixed in versions 3.15.2 and 4.3.2.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v3.1HIGHScore: 8.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

EPSS Trends

Current EPSS score: 0.39% Percentile: 32%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

  • CWE-407Inefficient Algorithmic Complexity

    An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Affected Systems

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • chainguardarangodb-3.12

    all | < 3.12.9.4-r35

  • chainguardargo-workflows-ui-4.0

    < 4.0.11-r0

  • chainguardauthentik-2025.12

    all

  • chainguardauthentik-2026.2

    all

  • chainguardauthentik-2026.5

    all | < 2026.5.7-r1

  • chainguardauthentik-fips-2025.12

    all | < 2025.12.6-r13

  • chainguardauthentik-fips-2026.5

    all | < 2026.5.7-r2

  • chainguardawx

    all | < 24.6.1-r56

  • chainguardcode-server

    < 4.136.2-r1

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguardeslint

    all | < 10.10.0-r1

  • chainguardfoxx-cli

    all | < 2.1.1-r11

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    all | < 19.1.8-r0

  • chainguardjupyter-base-notebook

    all

  • chainguardkatib-suggestion-hyperopt

    < 0.19.0-r40

  • chainguardkibana-8.19

    all | < 8.19.21-r2

  • chainguardkibana-8.19-bitnami

    all | < 8.19.21-r2

  • chainguardkibana-8.19-iamguarded

    all | < 8.19.21-r2

  • chainguardkibana-9.3

    all

  • chainguardkibana-9.3-iamguarded

    all

  • chainguardlerna

    all | < 10.0.1-r3

  • chainguardmongod-7.0-oci-entrypoint-compat

    all | < 7.0.41-r1

  • chainguardmongod-8.0-oci-entrypoint-compat

    all | < 8.0.32-r1

  • chainguardmongod-8.2-oci-entrypoint-compat

    all

  • chainguardmongod-8.3-oci-entrypoint-compat

    all | < 8.3.9-r1

  • chainguardopensearch-dashboards-2

    all | < 2.19.6-r19

  • chainguardopensearch-dashboards-2-fips

    all | < 2.19.6-r8

  • chainguardopensearch-dashboards-3

    all | < 3.8.0-r4

  • chainguardopensearch-dashboards-3-fips

    all | < 3.8.0-r2

  • chainguardpercona-server-mongodb-7.0-oci-entrypoint

    all | < 7.0.40_p22-r2

  • chainguardpercona-server-mongodb-8.0-oci-entrypoint

    all | < 8.0.29.13-r2

Showing first 50 affected entries in server-rendered view.

References (50)