A vulnerability was found in nodeca js-yaml up to 5.2.0. It has been classified as problematic. This impacts the function addItem of the file src/tag/sequence/omap.ts of the component Omap Handler. The manipulation leads to resource consumption. This vulnerability is listed as CVE-2026-59870. The attack may be initiated remotely.
| Vendor | Product | Versions |
|---|---|---|
| nodeca | js-yaml | >= 5.0.0, < 5.2.1 |
Updated description with new details, changed severity to HIGH, and marked the vulnerability as actively exploited.
Initial creation