Severity: high
CVE: CVE-2026-84375
Package: js-yaml @ 4.3.0
Vulnerable range: >=4.0.0 <4.3.2
Patched in: >=4.3.2
Dep paths:
lib__api-spec>orval>js-yaml
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
Reference: GHSA-2883-xcg3-v3hh
Filed automatically by .github/workflows/pnpm-audit.yml. The fix
work for this CVE belongs in its own task; see
docs/security-audit-public-2026-04.md §11 limitation 4 for the
policy. Either bump the affected dep (closes this issue on the next
scheduled run) or add an entry to scripts/audit/ignore-list.json
with a written reachability rationale and a re-evaluation date.
Severity: high
CVE: CVE-2026-84375
Package:
js-yaml@4.3.0Vulnerable range:
>=4.0.0 <4.3.2Patched in:
>=4.3.2Dep paths:
lib__api-spec>orval>js-yamlReference: GHSA-2883-xcg3-v3hh
Filed automatically by
.github/workflows/pnpm-audit.yml. The fixwork for this CVE belongs in its own task; see
docs/security-audit-public-2026-04.md§11 limitation 4 for thepolicy. Either bump the affected dep (closes this issue on the next
scheduled run) or add an entry to
scripts/audit/ignore-list.jsonwith a written reachability rationale and a re-evaluation date.