A vulnerability categorized as problematic has been discovered in nodeca js-yaml up to 5.2.1. Affected is the function
readFlowCollection of the file src/parser/parser.ts of the component Parser. Executing a manipulation can lead to infinite loop.
This vulnerability is registered as CVE-2026-73643. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.