11 Total advisories
11 Vulnerabilities
0 Malware
Dependency scanning
Check whether js-yaml is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-73643
js-yaml: Exponential parsing time in flow collections leads to denial of service
MEDIUM 5.3
CVE-2025-64718
js-yaml has prototype pollution in merge (<<)
HIGH 7.5
GHSA-5p4m-2wfm-xmqj
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
MEDIUM 5.3
CVE-2026-59870
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
MEDIUM 5.3
CVE-2026-53550
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
HIGH 7.5
CVE-2026-59869
js-yaml: YAML merge-key chains can force quadratic CPU consumption
HIGH 7.5
CVE-2026-84375
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
MEDIUM 5.3
CVE-2026-59868
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml
UNKNOWN
CVE-2013-4660
Deserialization Code Execution in js-yaml
MEDIUM 5.9
GHSA-2pr6-76vf-7546
Denial of Service in js-yaml
UNKNOWN
GHSA-8j8c-7jfh-h6hx
Code Injection in js-yaml
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes