npm vulnerability intelligence

js-yaml NPM Package
Vulnerability Check

YAML 1.2 parser and serializer

Critical MIT v5.2.3
Vulnerability Analysis OSV Live

js-yaml

v5.2.3 · MIT · 292,265,394 dl/wk

Advisory Breakdown

Critical 1
High 4
Moderate 5
Low 0

Severity Rating

Critical

10 advisories

Critical

Weekly downloads

292,265,394

Total advisories

10

Latest version

5.2.3

License

MIT

Known advisories

OSV records for the npm ecosystem

10
GHSA-2pr6-76vf-7546 moderate

Denial of Service in js-yaml

Affected: >=0 <3.13.0 Fixed in: 3.13.0 Updated Aug 4, 2021
View source
GHSA-52cp-r559-cp3m CVE-2026-59869 high

js-yaml: YAML merge-key chains can force quadratic CPU consumption

Affected: >=3.0.0 <3.15.0, >=4.0.0 <4.3.0 Fixed in: 3.15.0, 4.3.0 Updated Jul 21, 2026
View source
GHSA-5p4m-2wfm-xmqj high

JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported

Affected: >=4.0.0 <4.3.1, >=3.0.0 <3.15.1 Fixed in: 4.3.1, 3.15.1 Updated Aug 7, 2026
View source
GHSA-724g-mxrg-4qvm CVE-2026-59870 moderate

js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA

Affected: >=5.0.0 <5.2.1 Fixed in: 5.2.1 Updated Jul 30, 2026
View source
GHSA-8j8c-7jfh-h6hx high

Code Injection in js-yaml

Affected: >=0 <3.13.1 Fixed in: 3.13.1 Updated Aug 31, 2020
View source
GHSA-g796-fgmg-93mv CVE-2026-59868 moderate

js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml

Affected: >=5.0.0 <5.2.0 Fixed in: 5.2.0 Updated Jul 20, 2026
View source
GHSA-h67p-54hq-rp68 CVE-2026-53550 moderate

JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases

Affected: >=4.0.0 <4.2.0, >=0 <3.15.0 Fixed in: 4.2.0, 3.15.0 Updated Jun 29, 2026
View source
GHSA-mh29-5h37-fv8m CVE-2025-64718 moderate

js-yaml has prototype pollution in merge (<<)

Affected: >=4.0.0 <4.1.1, >=0 <3.14.2 Fixed in: 4.1.1, 3.14.2 Updated Jul 8, 2026
View source
GHSA-pm4m-ph32-ghv5 high

js-yaml: Exponential parsing time in flow collections leads to denial of service

Affected: >=5.0.0 <5.2.2 Fixed in: 5.2.2 Updated Jul 28, 2026
View source
GHSA-xxvw-45rp-3mj2 CVE-2013-4660 critical

Deserialization Code Execution in js-yaml

Affected: >=0 <2.0.5 Fixed in: 2.0.5 Updated Nov 8, 2023
View source

Checked Aug 12, 2026, 4:37 PM from npm and OSV.dev

Package metadata

From the npm registry

Package name
js-yaml
Ecosystem
npm
Latest version
5.2.3
License
MIT
Weekly downloads
292,265,394

Remediation boundary

What RequestGuard does — and doesn't — cover

RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.

Signup flows
Login attempts
API traffic

Data from npm registry and OSV.dev · Checked 8/12/2026, 4:37:28 PM