OurCVEs
Register
Back to feed
High
GHSA-2883-xcg3-v3hh
(CVE-2026-84375)

Published Sep 8, 2026

CVSS

7.5

HIGH

EPSS

Exploit Prediction Scoring System — the modeled probability of in-the-wild exploitation in the next 30 days.

Affected packages

0
Summary

js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources

Developer impact

Recommended action

Affected packages
Sources