HIGH7.5CVE-2026-59869js-yaml: YAML merge-key chains can force quadratic CPU consumption >= 3.0.0, < 3.15.0
MEDIUM5.3CVE-2026-59868js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml >= 5.0.0, < 5.2.0
MEDIUM5.3CVE-2026-59870js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA >= 5.0.0, < 5.2.1
MEDIUM5.3JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
>= 4.0.0, < 4.2.0
MEDIUM5.3js-yaml has prototype pollution in merge (<<)
>= 4.0.0, < 4.1.1
—Deserialization Code Execution in js-yaml
from 0, < 2.0.5