Skip to content

chore(security): bump js-yaml to >=4.3.0 (GHSA-52cp-r559-cp3m) [26_1]#34481

Merged
Alyar666 merged 1 commit into
DevExpress:26_1from
Alyar666:sec-jsyaml-261
Jul 24, 2026
Merged

chore(security): bump js-yaml to >=4.3.0 (GHSA-52cp-r559-cp3m) [26_1]#34481
Alyar666 merged 1 commit into
DevExpress:26_1from
Alyar666:sec-jsyaml-261

Conversation

@Alyar666

@Alyar666 Alyar666 commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

No description provided.

The existing override capped js-yaml at ^4.2.0, which still resolves to
the vulnerable 4.2.0. GHSA-52cp-r559-cp3m / CVE-2026-59869 (high) is a
quadratic-CPU DoS via YAML merge-key chains, patched in 4.3.0. js-yaml
is a transitive dev/build dependency only and is not shipped in any
published package.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@Alyar666
Alyar666 merged commit 5f504d8 into DevExpress:26_1 Jul 24, 2026
105 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants