Skip to main content

js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources

0
Medium
Published: 09/29/2026 (09/29/2026, 17:57:39 UTC)
Source: GCVE Database
Product: js-yaml

Description

A vulnerability in js-yaml versions 5.0.0 up to but not including 5.4.1 allows an attacker to cause excessive CPU consumption by exploiting how empty merge source mappings are counted. The maxTotalMergeKeys setting does not count empty mappings, enabling an attacker to craft YAML documents that cause the loader to perform O(N*K) work, leading to prolonged CPU usage. This can result in denial of service due to resource exhaustion. A patch is available that adjusts the counting method to include every merge source mapping as one budget unit.

CVSS v3.1

Score 5.3medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected software

npmghsa
js-yaml
Affected versions
>=5.0.0 <5.4.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 21:22:51 UTC

Technical Analysis

The js-yaml library's maxTotalMergeKeys configuration is intended to limit CPU usage by restricting the total number of merge keys processed. However, empty mappings are not counted towards this limit. An attacker can exploit this by repeatedly merging large sequences of empty mappings, causing the loader to iterate over all elements multiple times, resulting in O(N*K) CPU work while the limit remains unchanged. This leads to significant CPU consumption disproportionate to the configured limit. The issue affects versions >=5.0.0 and <5.4.1. The fix involves counting every merge source mapping as one budget unit in addition to counting its keys.

Potential Impact

An attacker can submit a crafted YAML document that triggers excessive CPU consumption during parsing, potentially causing denial of service by exhausting CPU resources. The vulnerability does not affect confidentiality or integrity but impacts availability due to prolonged CPU usage. The CVSS score is 5.3 (medium severity) with an attack vector of network, low attack complexity, no privileges required, no user interaction, and impact limited to availability.

Mitigation Recommendations

A patch is available for js-yaml that fixes this issue by counting every merge source mapping as one budget unit. Users should upgrade to version 5.4.1 or later to mitigate this vulnerability. Until patched, be cautious when processing untrusted YAML documents with merge keys enabled.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-r3ph-w7gj-g6xm
Osv Schema Version
1.4.0
Ecosystems
["npm"]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6abc27d2680226ef6846f930

Added to database: 09/29/2026, 21:04:18 UTC

Last enriched: 09/29/2026, 21:22:51 UTC

Last updated: 09/30/2026, 03:15:21 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses