Inefficient Algorithmic Complexity in js-yaml (npm) - CVE-2026-84375
Published: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in the js-yaml YAML loader when processing a crafted YAML document containing repeated merges of empty mappings. A remote attacker can submit a crafted YAML document to cause a denial of service.
In versions 3 and 4, merge support is enabled by default.
Affected software
Nautobot
How to mitigate CVE-2026-84375
Nautobot - addressed in versions 2.4.42, 3.2.5