CVE-2026-53550
CVE-2026-53550: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityMedium5.3
Medium [CVE-2026-53550] Denial of Service via crafted YAML merge keys
CVE-2026-53550Source published Source updated
js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerability is fixed in 4.2.0 and 3.15.0. A remote attacker can exploit this vulnerability by providing a specially crafted YAML document that repeatedly uses the same alias in a merge sequence. This can lead to algorithmic CPU exhaustion, causing the Node.js worker or event loop to be blocked for an…
- Affected products in this advisory
- Red Hat Hardened Images
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.4
- Red Hat Openshift Data Foundation 4.18
40 more entries in the full advisory.
- Source-reported affected versions
- < 4.2.0
- < 3.15.0
- Source-reported fixed versions
- 4.2.0
- 3.15.0
- nodejs26-main-26.4.0-1.3.hum1
- nodejs25-main-25.9.0-1.3.hum1
37 more entries in the full advisory.
- Mitigation guidance
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.