Your message dated Fri, 04 Sep 2026 10:27:09 +0000
with message-id <[email protected]>
and subject line Bug#1146637: fixed in node-js-yaml 4.3.2+~4.0.9-1
has caused the Debian Bug report #1146637,
regarding node-js-yaml: CVE-2026-84375
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1146637: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146637
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: node-js-yaml
Version: 4.2.0+~4.0.9-2
Severity: important
Tags: security upstream
Forwarded: https://github.com/nodeca/js-yaml/pull/797
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for node-js-yaml.

CVE-2026-84375[0]:
| js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until
| 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and
| lib/loader.js does not count empty mapping sources while processing
| the merge key <<. An attacker can alias a large sequence of empty
| mappings into many merge targets, causing O(N * K) processing while
| totalMergeKeys remains unchanged and the configured resource limit
| is never reached. A relatively small YAML document can therefore
| cause prolonged CPU consumption in applications that parse untrusted
| YAML, and merge processing is enabled by default on these release
| lines. This issue is fixed in versions 3.15.2 and 4.3.2.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-84375
    https://www.cve.org/CVERecord?id=CVE-2026-84375
[1] https://github.com/nodeca/js-yaml/pull/797
[2] https://github.com/nodeca/js-yaml/security/advisories/GHSA-2883-xcg3-v3hh

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: node-js-yaml
Source-Version: 4.3.2+~4.0.9-1
Done: Xavier Guimard <[email protected]>

We believe that the bug you reported is fixed in the latest version of
node-js-yaml, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated node-js-yaml package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 04 Sep 2026 11:49:45 +0200
Source: node-js-yaml
Architecture: source
Version: 4.3.2+~4.0.9-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers 
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 1146637
Changes:
 node-js-yaml (4.3.2+~4.0.9-1) unstable; urgency=medium
 .
   * Team upload
   * New upstream version (Closes: #1146637, CVE-2026-84375)
   * Drop CVE-2026-59869.patch: included
   * Build ES5 with @rollup/plugin-buble
Checksums-Sha1: 
 be65551052b8f90dc74b6385b1264b64b842a1cc 2607 node-js-yaml_4.3.2+~4.0.9-1.dsc
 cd82382c4f902fed9691a2ed79ec68c5898af4c2 3632 
node-js-yaml_4.3.2+~4.0.9.orig-types-js-yaml.tar.gz
 1567a65d19de82eed23001bed500dfcf29535603 1009589 
node-js-yaml_4.3.2+~4.0.9.orig.tar.gz
 d9dc30ad91f2f626b7b34398ccaf1c38646162fa 83328 
node-js-yaml_4.3.2+~4.0.9-1.debian.tar.xz
Checksums-Sha256: 
 9f9d9d27a2e06710c3f94d38e0ca656536276b30b0468f3e2edeb217b1cd4370 2607 
node-js-yaml_4.3.2+~4.0.9-1.dsc
 8c9a234188f42e35d0a4f9256c8ff2972b3215558c05b42fe96b8ac85d6094fd 3632 
node-js-yaml_4.3.2+~4.0.9.orig-types-js-yaml.tar.gz
 92f1e0420ec505e5565821d5728fc3fcec91c795609758a26c16942821b1cd00 1009589 
node-js-yaml_4.3.2+~4.0.9.orig.tar.gz
 9e970aa824fe2e242a82c09601503cc0511b9725977b72c0a15c0cd562692d97 83328 
node-js-yaml_4.3.2+~4.0.9-1.debian.tar.xz
Files: 
 da491091a73e535bd7abbfe63a342068 2607 javascript optional 
node-js-yaml_4.3.2+~4.0.9-1.dsc
 611e298d20865ccb5101e244867bd077 3632 javascript optional 
node-js-yaml_4.3.2+~4.0.9.orig-types-js-yaml.tar.gz
 a51dfc997da1611eb371de9344579fc6 1009589 javascript optional 
node-js-yaml_4.3.2+~4.0.9.orig.tar.gz
 8017bf6fe7710e3f2bb927a2b510eca3 83328 javascript optional 
node-js-yaml_4.3.2+~4.0.9-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmqalIgACgkQ9tdMp8mZ
7ukaKg/+MZWfvCodLvV6swA/Y5BcaYDP/zRLNHSEWn8ylQka/g4tK8BRkIu4i2fe
pCEbeeJtvyk4Gc9Zq2d+aBdg7gVLHiwm3vdDsMIUGNdfBD62+1oYfy1/XopiJcm6
h6+051JLaWXLmVXlZsQN8FPXaabKQ7D6W5jI9UNCnDigyR0PpVWy5aFfyg8WABb1
gRUJY06UW+WU2XOsSw1F9uo6ywVe6vO4PC6FxTpxmPRfXyBJMwzNizBZ9DKNSCDz
4q8w+8qtmW7gB1IebKs86z9L8d1yZT8h2MGS/0rPIvu727ZVEFp6padGJ9pzQc/O
mPCfjpUNMAwD95ak5MOpaRUdnuSspkQfDwBAUIM8aVIOBqJXAFP0yOEFwV5xt4Qu
jA4MmGCmtb6qF4vNwWI7e/DRzNeP5lNdNV4iXo5na+uQEP0NUbFKcGeXtMTN9d96
eG6Bx16AP0SGTn21g5xC+J2/9Efwl27OG/K0RqtCTGrLb9Kwakawwa19f7mENueD
4NxOePDc8ZX7PchLoHgmhUvI//BgY6pJvgheTI3p6zxICz640F+cH2TadY5wViun
dBHstcq0G5xAm3I6hkQD4cQXmh87Y1w2B0dp9ALclD7+f9obWxsYkKQHOWxAu1CA
woi6uhUYReslk/JiFACnJmCA8DR2lbHwJHGRFTxwQ+3Voby8XAQ=
=NKXS
-----END PGP SIGNATURE-----

Attachment: pgp2iLcnilKJk.pgp
Description: PGP signature


--- End Message ---
-- 
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to