By vendor
Nodeca vulnerabilities
Known CVEs affecting Nodeca products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-53550MEDIUM 5.3
js-yaml, a widely-used Node.js YAML parser, contains a denial-of-service vulnerability in its merge-key handling logic. An attacker can craft a malicious YAML document that exploits how the library processes merge operations (<<) by repeating aliases, causing the parser to consume excessive CPU time. The impact is significant for availability: a relatively small payload—just tens of kilobytes—can freeze a Node.js process for several seconds, disrupting application responsiveness or worker threads. The vulnerability has been patched in versions 4.2.0 and 3.15.0.