CVE-2026-84375

Red Hat Security Advisory: Red Hat Quay 3.10.26

Beschreibung

js-yaml ist ein JavaScript-YAML-Parser und -Dumper. Von Version 3.0.0 bis einschließlich 3.15.2 und 4.3.2 zählt maxTotalMergeKeys in `lib/js-yaml/loader.js` und `lib/loader.js` leere Mapping-Quellen nicht, während der Merge-Schlüssel << verarbeitet wird. Ein Angreifer kann eine große Sequenz leerer Mappings in viele Merge-Ziele umschreiben, was zu einer O(N * K)-Verarbeitung führt, wobei totalMergeKeys unverändert bleibt und die konfigurierte Ressourcengrenze nie erreicht wird. Ein relativ kleines YAML-Dokument kann daher eine anhaltende CPU-Auslastung in Anwendungen verursachen, die unsicheres YAML parsen, da die Merge-Verarbeitung standardmäßig auf diesen Versionen aktiviert ist. Dieses Problem wurde in den Versionen 3.15.2 und 4.3.2 behoben.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.5
Quelle: cna-v3
31.9 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.4 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-09-09 16:20 UTC
CWE-400, CWE-407

Weakness-Klassen (CWE)

  • CWE-400Class

    Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

    cwe.mitre.org →
  • CWE-407Class

    Inefficient Algorithmic Complexity

    An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-02 16:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-84375","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
  2. New CVE Received2026-09-01 22:17 UTC· security-advisories@github.com
    • Description: js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias a large sequence of empty mappings into many merge targets, causing O(N * K) processing while totalMergeKeys remains unchanged and the configured resource limit is never reached. A relatively small YAML document can therefore cause prolonged CPU consumption in applications that parse untrusted YAML, and merge processing is enabled by default on these release lines. This issue is fixed in versions 3.15.2 and 4.3.2.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    • CWE: CWE-407
    • CWE: CWE-400

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • axios

    axios0.31.1 – 0.33.0

  • axios

    axios1.15.1 – 1.18.0

  • facelessuser

    soup_sieve2.8.4

  • go

    golang.org/x/text

  • go

    stdlib1.26.0-0

  • go

    stdlib1.27.0-0

  • golang

    go1.26.0 – 1.26.2

  • golang

    go1.25.9

  • mobyproject

    buildkit0.31.2

  • nanoid_project

    nanoid3.0.0 – 3.3.17

  • nanoid_project

    nanoid5.0.0 – 5.1.16

  • nanoid_project

    nanoid5.0.0 – 5.1.6

  • nanoid_project

    nanoid3.3.16

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-84375