CVE-2026-73643
CVE-2026-73643: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh7.5
High [CVE-2026-73643] Denial of Service via exponential parsing in flow collections
CVE-2026-73643Source published Source updated
js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2, parsing a small YAML document can take exponential time when an application calls load() or loadAll() on untrusted input. In src/parser/parser.ts, readFlowCollection uses restoreState and calls parseNode a second time when a flow-sequence entry is recognized as a key: value pair. If the key is a nested flow sequence of the same shape, every level is parsed twice, causing O(2^n) work and allowing an input under 200 bytes to keep one CPU busy for minutes, block the Node.js event loop, and stall the process. No anchors, aliases, merges, tags, or nondefault options are required. This issue is fixed in version 5.2.2. A remote attacker could exploit this vulnerability by providing specially crafted YAML input containing…
- Affected products in this advisory
- Cluster Observability Operator 1.5.0
- Red Hat Ansible Automation Platform 2.2
- Red Hat Discovery 2
- Red Hat OpenShift AI 2.25
19 more entries in the full advisory.
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- 5.2.2
- cluster-observability-operator/monitoring-console-plugin-pf6-rhel9:1787597578
- ansible-automation-platform/bootc-automation-portal-rhel9:1788943531
- discovery/discovery-ui-rhel9:1788206196
15 more entries in the full advisory.
- Mitigation guidance
- To mitigate this issue, restrict applications from processing untrusted YAML input with affected versions of the `js-yaml` library. Implement strict input validation to ensure that only trusted and well-formed YAML data is processed. If the application is exposed to external, untrusted sources, consider isolating the application or implementing additional resource limits to prevent complete service disruption.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.