CVE-2026-84375 | nodeca js-yaml up to 3.15.1/4.3.1 Merge Key lib/js-yaml/loader.js maxTotalMergeKeys resource consumption
A vulnerability marked as problematic has been reported in nodeca js-yaml up to 3.15.1/4.3.1. This affects the function maxTotalMergeKeys of the file lib/js-yaml/loader.js of the component Merge Key. This manipulation causes resource consumption.
This vulnerability appears as CVE-2026-84375. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More