VDB
Sign up
MEDIUM5.9

GHSA-2pr6-76vf-7546

Denial of Service in js-yaml

Quick fix

GHSA-2pr6-76vf-7546 — js-yaml: upgrade to the fixed version with the command below.

npm install js-yaml@3.13.0

Details

Versions of `js-yaml` prior to 3.13.0 are vulnerable to Denial of Service. By parsing a carefully-crafted YAML file, the node process stalls and may exhaust system resources leading to a Denial of Service.

## Recommendation

Upgrade to version 3.13.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/js-yaml
Introduced in: 0Fixed in: 3.13.0
Fixnpm install js-yaml@3.13.0

References