MEDIUMnpm

js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA

js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA

CVE-2026-59870Published 2 weeks agoUpdated 6 days agoSource: OSV

Affected packages

  • js-yaml

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.41%
EPSS percentile
33.7%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 34%.

js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA | HackTribune