SCA: security update for yaml (GHSA-48c2-rrv3-qjmp)

medium Tenable Self-Hosted Container Security Plugin ID 439222

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- `yaml` is a YAML parser and serialiser for JavaScript. Parsing a YAML document with a version of `yaml` on
the 1.x branch prior to 1.10.3 or on the 2.x branch prior to 2.8.3 may throw a RangeError due to a stack
overflow. The node resolution/composition phase uses recursive function calls without a depth bound. An
attacker who can supply YAML for parsing can trigger a `RangeError: Maximum call stack size exceeded` with
a small payload (~2–10 KB). The `RangeError` is not a `YAMLParseError`, so applications that only catch
YAML-specific errors will encounter an unexpected exception type. Depending on the host application's
exception handling, this can fail requests or terminate the Node.js process. Flow sequences allow deep
nesting with minimal bytes (2 bytes per level: one `[` and one `]`). On the default Node.js stack,
approximately 1,000–5,000 levels of nesting (2–10 KB input) exhaust the call stack. The exact threshold is
environment-dependent (Node.js version, stack size, call stack depth at invocation). Note: the library's
`Parser` (CST phase) uses a stack-based iterative approach and is not affected. Only the compose/resolve
phase uses actual call-stack recursion. All three public parsing APIs are affected: `YAML.parse()`,
`YAML.parseDocument()`, and `YAML.parseAllDocuments()`. Versions 1.10.3 and 2.8.3 contain a patch.
(CVE-2026-33532)

Solution

Update the yaml library and its related packages to version 1.10.3 or later.

See Also

https://github.com/advisories/GHSA-48c2-rrv3-qjmp

Plugin Details

Severity: Medium

ID: 439222

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 3/26/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:P

CVSS Score Source: CVE-2026-33532

CVSS v3

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/25/2026

Vulnerability Publication Date: 3/25/2026

Reference Information

CVE: CVE-2026-33532

cwe: CWE-674