Junglewise Threat Intelligence

JS-YAML quadratic CPU consumption in !!omap resolution

Severity: low · CVSS 3.1 · Published 2026-08-06

Technologies: Js-Yaml.

Executive brief

JS-YAML is a widely-used JavaScript library for parsing YAML configuration files and data. Versions 3.x and 4.x contain a performance flaw in the ordered-map feature that allows an attacker to craft a YAML file causing the parser to consume excessive CPU time, blocking the application and affecting all concurrent requests. The vulnerability requires no authentication and can be exploited by sending a modestly-sized malicious YAML document, making it a serious denial-of-service risk for any service that accepts untrusted YAML input.

Technical details

The vulnerability exists in lib/type/omap.js where the resolveYamlOmap() function validates key uniqueness using Array.prototype.indexOf() inside a loop that iterates over each map entry. This creates O(n²) time complexity: as objectKeys array grows, each subsequent indexOf() call performs a linear scan, resulting in roughly 1+2+...+n comparisons for an n-entry !!omap. The !!omap type is enabled by default in the default schema, requiring no special configuration. The synchronous nature of yaml.load() means the CPU consumption blocks the Node.js event loop, stalling all concurrent requests in a process. The fix, already deployed in js-yaml 5.2.1+, replaces the linear scan with a Set-based lookup (O(1) per operation, O(n) overall). Versions 3.15.0 and 4.3.0 remain affected despite being the latest in their respective lines.

Affected products

  • js-yaml js-yaml 3.0.0 to 3.15.0
  • js-yaml js-yaml 4.0.0 to 4.3.0

Timeline

  • 2026-07-31: disclosed: Advisory published by js-yaml maintainers
  • 2026-08-06: patched: js-yaml 3.15.1 and 4.3.1 released with fixes
  • 2026-05-01: other: Same weakness fixed in js-yaml 5.2.1 but fix never backported to 3.x and 4.x

References