[Git][security-tracker-team/security-tracker][master] Track fixed version via unstable for CVE-2026-84375/node-js-yaml

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 4 13:18:09 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4c088739 by Salvatore Bonaccorso at 2026-09-04T14:17:34+02:00
Track fixed version via unstable for CVE-2026-84375/node-js-yaml

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1661,7 +1661,7 @@ CVE-2026-84425 (A vulnerability was found in zhayujie CowAgent up to 2.1.3. This
 CVE-2026-84423 (A vulnerability has been found in Casdoor up to 4.0.0. This affects an ...)
 	NOT-FOR-US: Casdoor
 CVE-2026-84375 (js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15. ...)
-	- node-js-yaml <unfixed> (bug #1146637)
+	- node-js-yaml 4.3.2+~4.0.9-1 (bug #1146637)
 	[trixie] - node-js-yaml <no-dsa> (Minor issue)
 	[bookworm] - node-js-yaml <postponed> (Minor issue)
 	NOTE: https://github.com/nodeca/js-yaml/security/advisories/GHSA-2883-xcg3-v3hh



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4c0887396bc7522e6a60eac3fd66350d71990936

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4c0887396bc7522e6a60eac3fd66350d71990936
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/f052cbda/attachment.htm>


More information about the debian-security-tracker-commits mailing list