CVE-2026-84375 | nodeca js-yaml up to 3.15.1/4.3.1 Merge Key lib/js-yaml/loader.js maxTotalMergeKeys resource consumption

SecurityVulns

A vulnerability marked as problematic has been reported in nodeca js-yaml up to 3.15.1/4.3.1. This affects the function maxTotalMergeKeys of the file lib/js-yaml/loader.js of the component Merge Key. This manipulation causes resource consumption.

This vulnerability appears as CVE-2026-84375. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More